What happened
A dealership executive posted a message their store had received from Instinct, a general AI personal assistant, writing on behalf of a customer. The customer wanted a 2026 Volvo XC90 and had been specific: a B5 or B6, not the plug-in hybrid. Six seats, meaning two individual chairs in the second row. Ultra trim preferred, Plus acceptable. Onyx Black or Vapour Grey.
For any matching vehicle, it asked the dealership for the trim, the exterior and interior colors, the VIN or stock number, whether it was available now or when it was expected to arrive, and whether it could be leased. It called the message an inventory inquiry, not a request to hold a vehicle, and it didn't share the customer's contact details. Instinct isn't a car-buying service. It's a general assistant, and in September it started giving each user's agent its own email address so it can write to businesses directly. A car dealer is just one of the businesses it can write to.
It also isn't the first time software has contacted a business for a customer. Google already places automated calls to businesses in most US states to check prices, availability and wait times for people who ask. Meta launched its Muse agent in September and says it's experimenting with calls to businesses. At least one car-buying service sells an AI that emails dealers and negotiates for the buyer. The dealership email is useful because it's so specific, not because it's new.
The email isn't the innovation
Businesses have received inquiries by email for as long as there's been email. What matters is the work that happened before this one existed.
Something interpreted what the customer wanted and turned it into a specification. It narrowed the requirements: two engine variants, two trims in order of preference, two colors. It picked this dealership out of every Volvo store it could have contacted. It contacted the dealer through the one channel every dealership has. It asked for the fields that decide whether a deal can happen. And it asked for exactly what the next step needs: VIN or stock number, arrival date and lease eligibility.
A shopper used to do the first part alone, across a dozen tabs and a few phone calls. In this case software did it. The email was just the transport.
Software did the narrowing, then came to the business for the part only the business knows.
The questions were operational, not promotional
None of what it asked for is on a dealership's homepage, and very little is reliably on a vehicle detail page. It lives in the dealer management system, the OEM allocation portal and the heads of the sales team. And it changes constantly: a car in transit on Monday is sold on Wednesday, and lease programs change monthly.
That points at a split that matters for every business. Durable facts (who you are, where you are, what you sell, your policies) change over months or years, live on the website and listings, and go wrong by drifting apart. Operational facts (what you have now, when, for whom, at what capacity) change over hours or days, live in the systems that run the business, and go wrong by going stale or never being exposed at all.
Most of what the industry calls AI visibility is about durable facts, and it matters: an assistant can't qualify a request against a dealer whose hours or brands are wrong. The anecdote is about operational facts. They need a source, a timestamp, a freshness rule and an honest answer when nobody knows.
Operational truth needs provenance and freshness, not just structure.
Unknown is a valid answer
Say an agent asks whether a dealership has a black six-seat XC90 B6 Ultra. The inventory feed lists one, but the record hasn't been updated in four days. Or the car is allocated and hasn't shipped, so it isn't in the feed yet. The tempting answer is “no match.” The correct answer is “unknown”: here's the last confirmed status, here's when it was checked, here's how to ask a person.
A false no costs the business the customer, and nobody finds out. The shopper's assistant moves on to the next store, and nothing in the dealer's analytics shows it happened. So a unit's status has more than two values: available, incoming, allocated, held, sold or unknown, each with where it came from and when.
A missing fact must never become a confident no.
Why agents end up emailing, and what replaces it
If you build an assistant that shops for people, email is a reasonable choice today. Every business has an address, nobody has to approve your integration, and a person can answer anything. It's also slow and unstructured. Someone has to read the message, look up four systems and reply by hand.
The alternatives exist now. MCP, the Model Context Protocol, is an open standard for letting an AI application call outside tools and read outside data. Anthropic introduced it in 2024 and donated it in December 2025 to the Agentic AI Foundation, a Linux Foundation fund. The current spec requires the host to get the user's consent before it calls a tool.
ChatGPT plugins are OpenAI's current name for its integrations, not the 2023 plugins. Each is a package of instructions, an optional MCP server and optional interface, reviewed before it's listed. OpenAI's docs say to put live data, authentication and controlled actions in the MCP server and to enforce authorization there on every request. Claude connects to remote MCP servers as connectors, and tools that change something always prompt the user. Meta's Muse asks the person before it sends or buys anything. Commerce protocols from OpenAI and Stripe and from Google handle checkout for approved retail merchants.
Two things stand out. Every platform has reached the same rule: reading is easy, and anything that changes something needs a declared permission and a person's say-so. And most of what's live is built for retailers with catalogs and checkout. A dealership, a roofer or a med spa sells something that needs a conversation first, so the honest next step for an agent is a structured inquiry, not a purchase.
Each protocol is a door. What matters is what's behind it.
Build the business interface once
The mistake to avoid is treating each AI platform as its own project: a ChatGPT version of your inventory, a Claude version, a version for whichever assistant launches next quarter, each with its own copy of the facts, its own idea of what's allowed and its own drift.
The layers we build toward run in one direction. The business's own systems feed one record of durable facts with provenance. Operational facts sit on top with a source, a timestamp and freshness rules. Controlled capabilities say what software may read, ask or do, and who approves it. Agent interfaces, like MCP, APIs, plugins and apps, expose those capabilities. ChatGPT, Claude, other assistants and future agents are clients of the interfaces. Observation, evidence and remediation close the loop.
In that picture a plugin is packaging, MCP is an adapter, and the model is never the authority on what's true or what's allowed. That's also why the protocol isn't the moat. A standard is supposed to become ordinary. What stays hard is facts the business has confirmed, live data with honest freshness, models that understand a vertical, permissions, evidence of every action, one build serving every assistant, and checking what the assistants actually do with it.
Build the business interface once. Let many authorized AI systems use it.
The ladder: discover, understand, qualify, contact, act
The old web journey was search, click, browse, fill in a form, wait. The one the anecdote points to is different. Discover: can the agent identify the dealership and what it sells? Understand: can it read trustworthy facts about inventory, policies and services? Qualify: can it tell whether this dealership can meet this exact request, like a six-seat 2026 XC90 B6 in black that can be leased? Contact: can it send a structured inquiry, quote request, callback request or test-drive request that reaches a person? Act: later, and only with the business's explicit permission, can it schedule, hold or start a transaction?
The first four are useful long before the fifth exists, and the risk climbs steeply at the last rung. Answering whether a unit is available can't hurt anyone if the answer is honest. Holding a car blocks a sale. Booking a test drive takes a salesperson's hour. Starting a lease application touches money and credit.
So every action that commits the business has to clear the same list: authentication, authorization, rate limits, human approval where time or money is at stake, spam protection, idempotency, validation, an audit log, replay protection, and a kill switch per business and for everything. A callable action is a promise that the business will respond. The assistant in the anecdote drew that line itself: an inquiry, not a hold.
Contact comes before act, and act needs the business's permission.
Beyond automotive
Automotive is a clean example because inventory makes operational facts easy to picture. The same structure shows up anywhere a customer's question depends on today.
A restaurant gets asked for a table for six at 7:30 with gluten-free options; the facts are the menu, dietary handling and tables, and the risky action is reserving. A home-services company gets asked whether it serves a town and can inspect this week; the facts are service area, job fit and crew capacity, and the risky action is booking. A med spa gets asked whether a provider offers a treatment with an opening Thursday. A hotel gets asked for two rooms, three nights, pets allowed. A store gets asked for a size and color for pickup today. A supplier gets asked about stock and lead time on 200 parts. A law firm gets asked whether it handles a kind of case in a county and can book a consult.
Each vertical needs its own model of what a fact is. A table isn't a vehicle, and renaming fields in a generic schema won't make it one. But the layers are the same: durable facts, live facts with a clock, controlled actions, an interface any authorized assistant can use, and evidence of what happened.
The question applies to every business that has something a customer might want today: can an AI agent actually do business with you?