Wajo's Fo Agent Can Call, Email and Pay on Its Own, Beating Rivals at Getting Things Done Wajo, the startup founded by former Google DeepMind engineering lead Shivani Poddar, launched its flagship personal agent Fo on September 29, which completed 71% of 104 real-world tasks on its own versus 42% for open-source rival OpenClaw and passed 94% of safety checks against OpenClaw's 74%, according to Wajo's own published fieldnotes. Fo is given a phone number, an email address and a single-use payment credential per purchase, and hands tasks it cannot finish to a human executive assistant rather than guessing. Wajo's benchmark figures have not been independently reproduced, and the company's terms place responsibility for what the agent authorizes on the user. She spent years at DeepMind watching frontier models hit their limits. Now Fo gets a phone number, an email address and a single-use card for every purchase, and beat a rival 71% to 42% on real-world errands. On September 29, Shivani Poddar launched Fo, the flagship agent from her new startup Wajo. She spent years leading engineering at Google DeepMind, watching frontier models up close and seeing exactly where they still fall apart, and Fo is built around a blunt admission: the AI still can't do everything, so give it a phone, an inbox, a voice, and a human backup for the parts it can't handle. The pitch is specific and testable, which is rare in this category. In 104 real-world tasks, Fo completed 71% on its own, compared with 42% for OpenClaw, the open-source assistant Wajo used as its benchmark rival. Fo also passed 94% of safety checks, meaning it stayed within its instructions and didn't leak private information, against a 74% rate for OpenClaw in the same trap runs, according to Wajo's own published fieldnotes. When Fo hits a wall, whether that's a phone tree with no good options or a request outside its authority, it hands the task to a human executive assistant rather than guessing. That handoff is the actual product. Most personal AI pitches this year have leaned on the fantasy that the model alone can do it all: book the table, cancel the subscription, argue with the airline. Poddar built Fo around the opposite bet, that a mixed team of software and people beats software alone, at least for now. Early testers cited by Wajo describe Fo making real phone calls and negotiating a fee waiver with a telecom provider. It's checked a restaurant's delivery radius abroad, too - the kind of tedious errand that eats an afternoon and rarely feels worth automating until you don't have to do it yourself. Wajo's headline claim is that a merchant never sees your real card, and Fo never sees it either. Each purchase runs through a single-use payment credential instead. The mechanics behind that promise aren't uniform, though. For merchants that already support newer agent checkout standards, Fo can use a single-use token generated for that one transaction. For everyone else, and most small businesses still fall in that bucket, Fo pays another way: a card Wajo itself controls, charging the user afterward, or a saved payment method with explicit approval first. Four different routes, one promise. Meta's Muse AI agent gave away a user's home address during a marketplace deal https://startupfortune.com/metas-muse-ai-agent-gave-away-a-users-home-address-during-a-marketplace-deal/ Meta's Muse AI agent gave away a user's home address during a marketplace deal - how Meta's Muse agent exposed user home address https://startupfortune.com/metas-muse-ai-agent-gave-away-a-users-home-address-during-a-marketplace-deal/ - AI assistant privacy risks in Facebook Marketplace deals https://startupfortune.com/metas-muse-ai-agent-gave-away-a-users-home-address-during-a-marketplace-deal/ It's a sensible design given how uneven merchant infrastructure still is. But it also means the privacy guarantee is doing more work in some transactions than others, and Wajo's terms put the responsibility for what the agent authorizes back on the user. None of Wajo's benchmark numbers have been independently reproduced yet. They come from Wajo's own testing, published on its own blog, not from a neutral third party. That's worth saying plainly, because a 71-versus-42 gap is the kind of number that's easy to repeat and hard to verify from outside. Why this is landing now Fo isn't launching into a quiet market. Shopify said this week it's opening checkout, including Shop Pay, to browser-based AI agents across its merchant base, using a protocol built for agents that operate inside a buyer's own browser session. Robinhood went further. At its HOOD Summit in Houston on September 29, it unveiled new trading agents built on OpenAI's and Anthropic's models for a mass consumer base. That's months after its original agentic trading rollout drew more than 15,000 accounts and, according to the company, roughly 30 million tool calls a day. The infrastructure for agents to act with money is being built in real time, by real platforms, right now, this week. Against that backdrop, Fo's numbers matter less as a marketing claim and more as a data point. Most of what's been published about agentic commerce so far is either a platform's own case for why it built the feature, or hype with no task-completion figure attached at all. Wajo at least put a number on the table: 71%, tested against a named rival, with a stated failure mode built into the product instead of hidden from it. Whether that number holds up outside Wajo's own test set is the real question. It's one only outside researchers or a wave of real users will answer. For now, sign-ups are open at wajo.ai. The honest way to describe where autonomous purchasing agents actually stand today: better than most people assume, worse than the pitch decks claim, and still leaning on a human in nearly three of every ten cases. AI Agent Swarm Breached 395 Organizations Through PaperCut Flaws in Hours https://startupfortune.com/ai-agent-swarm-breached-395-organizations-through-papercut-flaws-in-hours/ AI Agent Swarm Breached 395 Organizations Through PaperCut Flaws in Hours - AI agent swarm compromised PaperCut servers globally https://startupfortune.com/ai-agent-swarm-breached-395-organizations-through-papercut-flaws-in-hours/ - Russian threat actor used AI agents for cyberattacks https://startupfortune.com/ai-agent-swarm-breached-395-organizations-through-papercut-flaws-in-hours/ Also read: AIB Data Centers Ditched Bitcoin Mining and Landed a 12-Year Nebius Deal https://startupfortune.com/aib-data-centers-ditched-bitcoin-mining-and-landed-a-12-year-nebius-deal/ • HP Is Putting Perplexity on New PCs While Seven Publishers Sue It https://startupfortune.com/hp-is-putting-perplexity-on-new-pcs-while-seven-publishers-sue-it/ • Multicoin Capital Backs Grass, the Crypto Network Now Feeding AI Search https://startupfortune.com/multicoin-capital-backs-grass-the-crypto-network-now-feeding-ai-search/ This article is posted in AI News https://startupfortune.com/category/ai/ , check it out for more related stories. Join the discussion Open in the community → https://startupfortune.com/community/ Almost there. Sign in and your reply posts straight away.