The AI agency calling you was a dropshipper last year
A wave of inexperienced sellers is working small business phone lists right now, and the liability lands on you, not them. The full anatomy of the grift, and how to not be the bag holder.
I spent 26 years in tech before I started writing this newsletter. I have watched a few gold rushes up close. So when my feed filled up this year with 22-year-olds selling "AI automation agencies" to small businesses, and an equally loud crowd selling courses on how to start one, my gut said: I have seen this movie, and it ends the same way every time.
This week I put my agent to work testing that gut feel against actual data. Four research lanes, about a hundred sources, several days of forum archaeology. The gut feel held up, and then some. What I found was worse than I expected, and it is not a prediction. It is happening now. If you run a small business, you are the market these people are selling into, and this issue is about making sure you are not the one holding the bag when it ends. Because here is the part almost nobody selling this stuff will tell you: when their system lies to your customer, the legal exposure is yours.
The machine that manufactures your cold calls
Start with the numbers, because they are wild.
Search interest in "AI automation agency" was near zero before mid-2023, when a YouTuber coined the term. It hit its all-time peak this summer. His free community for aspiring agency owners has over 330,000 members. Another prominent one has around 420,000. An analysis of Skool's top 1,000 communities from last August found 94 AI-automation communities with over 800,000 combined members, 97% of them free tiers that funnel into paid programs running $5,000 to $7,000. The pitch, in the actual marketing copy: no coding required, no experience required, land small business clients in your first month.
Read that pitch again as an engineer and you see the whole problem. "No coding required" is not an entry requirement. It is a confession about what the graduates cannot do.
That is the supply side of your cold calls. Hundreds of thousands of people, most with no technical background and no operating history, told that your business is their first client.
The teach-versus-do math tells you where this economy actually lives. One prominent community runs about 3,700 paid members at $129 a month. That is roughly $5.7 million a year from teaching, next to a claimed $1 million a year from the agency work itself, a gap members themselves have started questioning. The agency is the marketing. The course is the business. One accelerator program hides its price until you are on a sales call, offers no refunds, and gates its guarantee behind proof that you sent 250 cold emails a day. Think about what that guarantee optimizes for. Not whether the graduate can build anything. Whether they can spam you.
And the regulator has already met these people once. In February 2024 the FTC hit a coaching operation called Automators with a $21.7 million judgment and lifetime coaching bans. Their history: they sold Amazon dropshipping automation, and when that wave died they relabeled the same offer with "AI." Same playbook, new costume, prosecuted under the new name. The FTC followed up with a whole enforcement sweep called Operation AI Comply aimed at deceptive AI business claims. That is the lineage of the industry cold-emailing you this week.
What they are selling you right now
The offers evolved, and it matters that you know the current catalog, because the ticket sizes went up. In late 2024 these agencies sold workflow automations wired together in Make or n8n for a few thousand dollars. That business died first. By early 2026 the community consensus in their own forums was blunt: simple automations are dead, anyone can build basic flows with AI prompts now. So the survivors moved upmarket, and today the pitch deck says:
The "AI employee." An agent that answers your phone, qualifies leads, books appointments, and "reactivates your old lead list" with automated calls and texts while you sleep. Sold as zero missed calls, captured revenue, no payroll. Frequently a white-labeled voice platform that costs the agency about five to nine cents a minute, resold to you at $500 to $1,500 a month plus setup.
The "autonomous agent team." One agent scrapes leads, another writes personalized outreach, another sends it, a coordinator routes everything. The demo is genuinely impressive. Sold for $5,000 to $15,000 and up.
The "AI operating system for your business." The big-ticket item: a $25,000 to $60,000 engagement to wire agents through your CRM, your inbox, your invoicing, your document flow. The seller is often months removed from a course, assembling this on top of the same frontier-model subscriptions you can buy yourself.
Notice what happened. As the tools got more powerful, the sellers did not get more careful. They got more ambitious. The same person who could not safely ship a chatbot last year is now selling you an autonomous system with its hands on your invoices and your customer list. The blast radius scaled with the ticket price, and the engineering discipline underneath scaled with neither.
And the lies stayed identical, because the lies are the product. You have seen them: passive income while you sleep. One person, agency output, zero payroll. Ninety days to $10k a month. There are 36 million small businesses that need this. Countdown timers on digital products with no seat limits, resetting every week. Screenshots of revenue with no mention of refunds, churn, or the cost of the ads that bought the screenshot. Every one of these is a claim about a services business, which lives or dies on retention, made by people whose median client relationship is measured in weeks.
Why the model itself fails, not just the practitioners
I want to be precise here, because "young and inexperienced" is not actually the core defect. The model fails structurally. If a talented, honest 22-year-old ran this playbook flawlessly, it would still collapse under them, for five reasons the courses never mention.
One: there is no moat, so there is no margin. The agency resells tools you can buy directly, marked up ten to twenty times. The platforms they build on sell to you too, on purpose. The $97-a-month all-in-one platform that half these agencies white-label now ships its own AI receptionist, chat, and content tools natively, unlimited use, flat fee. When your supplier competes with you for your own customer, you do not have a business. You have a head start that expires.
Two: the churn math is fatal. A healthy retainer agency loses about 1.6% of clients a month. A consultant who has deployed AI agents into more than 20 small businesses reports most installs failing within 60 days. You cannot run a retainer business on a product that dies faster than the invoice cycle. This is the same arithmetic that capped the social media agency wave, and this wave inherited it with a faster-decaying product.
Three: the demand they were promised does not exist at retainer prices. Vendor surveys say 58 to 76% of small businesses "use AI." The Census Bureau and Federal Reserve, using the strictest definition, put real production use under 10% for small firms. The gap between those numbers is people using ChatGPT sometimes. That is not a $1,500-a-month buyer. The course sellers quoted the vendor number to 800,000 students. The students are discovering the Census number one ignored cold email at a time.
Four: the platform risk is uninsurable. When a frontier lab replaced its flagship model last year, one operator described client builds that "literally became dumbbells overnight". The agency controls neither the model, nor the platform, nor the APIs underneath. A real engineering shop manages that risk with abstraction layers, fallbacks, version pinning. A course graduate does not know those words.
Five: even the winners lose. The most instructive data point in my whole research pile: a founder who did everything right, built a real AI agency to $80,000 a month over three years, and shut it down in January anyway. His stated reason: brutal margins. The ceiling of doing this well is a hard services business with bad economics. The floor is the 70% figure a recruiter in the space reported last September: of the AI-agent specialists he interviewed, 70% came from agencies that had already closed or pivoted into selling education. The wave is eating itself in public, and the marketing has not slowed down at all. As one Redditor summarized the closures thread: the blind helping the blind.
That last pivot deserves a beat of your attention. When these agencies fail, they do not exit the economy. They become teachers. "They failed selling agents," as the most cutting comment in a 1,700-upvote practitioner thread put it, "so have now pivoted to selling to people who want to know how to sell agents." The grift does not end. It compounds. Every collapsed agency is a new course, and every new course is a thousand new cold calls to your front desk.
Why their builds fall apart in production
Underneath the bad economics is the technical rot, and this is the part I am most qualified to tell you about, because I spent a career watching what happens to systems after the demo.
A demo is a system on its best day. Production is every day after that. The gap between the two has real names: systems thinking, failure-mode design, testing, monitoring, data validation. None of it is glamorous. All of it is the actual job. The course-taught wave skipped the entire thing, because you cannot teach operational judgment in six weeks to someone who has never operated anything.
The receipts from this year alone:
They automate a caricature of your business. An automation is a claim about how your business works: this input always looks like this, this step always follows that. A builder who has never run a business does not know where those claims break. One developer described watching agencies get fired after a $150,000 "company brain" project where the data was never cleaned and the automations quietly drifted, built by, in his words, consultants with zero background in tech. Garbage in was not in the course.
Nothing is tested, because they do not know what testing is. Real engineering tests the unhappy paths: the weird input, the API that times out, the customer who asks something sideways. The no-code wave tests the demo path and ships. A practitioner with 40-plus delivered projects wrote in May that half his pipeline is now founders who paid $50,000 for an agent build that is "bleeding tokens, can't be audited, and falls over the moment a customer does something unexpected." He rebuilds them as boring $4,000 automations. The fix for the fancy build was a tenth the price, done properly.
They fail silently, which is the most expensive way to fail. A field report from August: a business owner's AI agent had been quoting wrong prices and sending invoices with bad line items for weeks. It never hesitated, never flagged anything, because these systems do not know when they are wrong. The consultant who reported most installs failing within 60 days described the pattern that causes it: the agency "built it, declared victory, and walked away." No monitoring, no alerts, nobody watching. The system rots quietly until a customer complains, and then the owner concludes AI does not work.
Customer-facing AI without guardrail engineering is a standing liability. The r/sales crowd figured out this year that if you keep talking to a chatbot receptionist, it will eventually "ignore its programmed guardrails and just do whatever you ask." People are manipulating these bots into promising 100% discounts. Prompt injection, input validation, privilege limits: security concepts the person who wired your phone line to a language model last month has never heard of. One builder in that world said the quiet part out loud: a 19-year-old shipping one of these "with no regard for security, failure modes, or how it feels to a customer when it whiffs, that's the real danger."
And the desperation shows. Some AI receptionist vendors now add fake keyboard-typing sounds and fake background laughter to disguise the bot from your customers. When your vendor's product strategy is tricking the people you serve, the trust you spent years building is what they are spending.
None of this is because AI is bad. Every bit of it is because a probabilistic system that talks got treated like a light switch. People who have shipped software know the difference in their bones. People who bought a course last spring are finding out on your customers.
The liability lands on you
Now the part that should genuinely scare you, and I will flag clearly where I move from record to speculation.
The record first. In 2024, a Canadian tribunal ordered Air Canada to pay damages after its website chatbot invented a bereavement fare policy that did not exist. A customer relied on it; the airline refused to honor it. Air Canada actually argued that the chatbot was a separate legal entity responsible for its own actions. The tribunal called that submission remarkable and found the company liable for everything on its own website, chatbot included. That is the precedent: the business that deploys the bot answers for the bot.
Also on the record: the FCC ruled in February 2024 that AI-generated voice calls fall under the TCPA, the robocall statute, which carries statutory damages of $500 to $1,500 per call. Read that against the "reactivate your old lead list with AI calls and texts" package being sold to contractors, dentists, and med spas right now. Consent rules for automated outbound contact are strict, the penalties are per call, and there are attorneys who make a living on exactly this. The kid who set up your "database reactivation campaign" did not mention any of that, because nobody mentioned it to him.
Now the speculation, plainly labeled: I think the next phase of this wave is legal, and I think the small business ends up holding nearly all of it. Walk through it. Your AI receptionist misquotes a price and a customer relies on it: Air Canada logic says that is your misrepresentation. Your outbound AI caller hits people who never consented: those are your TCPA violations, at your number, in your name. Your agent-run automation mangles invoices for six weeks: your books, your customer relationships, maybe your tax filings. Meanwhile the agency that built it operates with no professional liability insurance, no meaningful assets, sometimes not even an LLC, running on a contract template from a course Discord, if there is a contract at all. Suing them would be winning a judgment against a logo. You will eat the loss, and they will pivot to teaching.
I am not a lawyer and none of this is legal advice. But I have watched enough technology waves to know that the lawyers always arrive, they arrive after the damage, and they bill the party that still has money. In this ecosystem, that party is you.
How to identify it
The tourists and the real implementers pitch you the same words. The difference shows up under six questions, and every one of them is really a systems-thinking test wearing street clothes.
Ask what they built before this year. Not what tools they use. What they have operated, shipped, or fixed, for businesses like yours, with dates. Someone with real history will answer in specifics and probably tell you about something that went wrong, because everyone with real history has scar tissue. Someone without it will pivot to a demo.
Ask what happens when it breaks at 2am on a Saturday. Who notices, how fast, and what the rollback is. This is the monitoring question, and it is the single fastest filter I know. An operator answers with mechanics: alerts, a fallback to a human, logs, an escalation path. A course graduate answers with a blank look, because the course ended at deployment.
Ask how they tested it. Specifically: what did you try to break? What happens when a customer asks something off-script, when the API is down, when the data is malformed? If the answer amounts to "we ran it and it worked," you are looking at a system that has been demonstrated, not tested. The difference costs about one angry customer to discover.
Ask who eats the liability. Do they carry errors-and-omissions insurance, and will they show you the certificate? Does the contract indemnify you if their system misrepresents something to your customer or sends messages the law says it should not? Watch the face when you ask. An established shop has heard these questions. A course graduate has not, and the flinch is your answer.
Ask them to price against an outcome, not a retainer. The failed-in-60-days pattern has a consistent shape: a flat monthly fee for a system nobody measures. Implementers who survive price against something you can count: hours saved, calls answered, jobs booked. If the value cannot be counted, ask why you are paying monthly for it.
Watch for course-funnel mechanics aimed at you. Countdown timers. "Three seats left this month." Pressure to sign on the sales call. Refunds gated behind hoops. These are guru techniques, and when they show up in a services pitch, you are talking to someone running their mentor's script.
One more tell, and it is the big one: if the person selling you AI services also sells a course about selling AI services, you already know which business is real.
How to fix it
First, the reframe, because the data cuts both ways and I want to be straight about it.
Small business demand for AI help is real. Goldman Sachs surveyed over 1,200 small business owners this February: 76% have adopted AI somewhere, 93% of those say it helped, and yet only 14% have it wired into their core operations. The gap between "tried ChatGPT" and "AI runs part of my business" is enormous, and it is exactly where the value sits. The tragedy of this wave is that a real need got flooded by unqualified sellers, and every burned owner makes the market harder for the few who know what they are doing.
So the fix is not "avoid AI." It is: stop outsourcing your judgment about it.
Run the pilot yourself before you take any meeting. Pick one repetitive process that annoys you. Spend one afternoon seeing how far you get with the tools you already have, including the AI baked into software you already pay for. Two outcomes, both good: either you solve it for under $100 a month and learned the retainer was never necessary, or you hit a real wall and now know exactly what to hire for. A buyer who has touched the tools is nearly impossible to oversell. In that Goldman survey, owners asked for training and resources over vendors by a wide margin. They are right.
If you do hire, hire an operator, not a reseller. The six questions above filter most of the field. Beyond them: demand references from businesses that have paid for six months or more, insist on owning your own accounts and data so firing them does not break your business, and start with a small fixed-scope project before any retainer. Real implementers exist. The good ones niche into one industry, price against measured outcomes, put humans in the loop where errors cost real money, carry insurance, and treat this like consulting with tools attached. They will pass every one of these checks without flinching, and they will respect you more for running them.
Hold customer-facing AI to a higher bar than back-office AI. A bot that drafts your emails can be mediocre while you review its work. A bot that talks to your customers cannot, because its mistakes are made in your name and, as the case law now shows, on your legal tab. If anyone proposes pointing an AI at your phone line or your inbox unsupervised, the burden of proof goes way up: guardrail testing, a human handoff path, call review, consent compliance on anything outbound, and a kill switch you control. The same owner who would never let a new hire talk to customers without training will happily point an untested bot at their phone line. Do not be that owner.
If someone you know is buying the course: the sellers' own communities are full of people who paid $5,000 to $7,000 and discovered the hard part was never the software. It was sales, service, and operational judgment, the things you cannot buy a shortcut for. The people making real money in that world niched hard, learned an industry deeply, learned to test and monitor what they shipped, and did the work. Which is to say: they became operators. There was no shortcut after all.
The window for the tourists is closing. Platform vendors are absorbing the simple use cases, buyers are getting burned and getting smarter, the lawyers are warming up, and the same gurus who sold this wave are already testing the next pitch. Your window is different. You know your business, you can measure your own outcomes, and the tools have never been cheaper or easier to try. The gap between you and the AI-run version of your business was never going to be closed by a stranger with a six-week-old logo and an untested workflow. It gets closed by you, one boring, tested, monitored process at a time.
Hit reply and tell me what's on your bench this week. I read every one.