OTWopentechwire
Tech Intelligence, Openly Wired
Startups

Why a DeepMind Veteran Is Building an AI Agent That Hires Humans

Shivani Poddar's Wajo enters a crowded personal-assistant market with virtual cards, human task delegation, and a pitch centred on privacy. Vinod Khosla is backing the bet.

PN
Priya Nair
Startups Reporter · Bengaluru
Oct 9, 2026
7 min read
Why a DeepMind Veteran Is Building an AI Agent That Hires Humans
Credit: Wajo

The Privacy Pitch in a Crowded Market

The AI agent wars have intensified sharply this autumn, with Meta, OpenAI, and a wave of well-funded startups racing to place assistants inside users' messaging apps. Into this field comes Wajo, a personal-agent platform founded by Shivani Poddar, who spent years in engineering roles at Meta, Google, and DeepMind. Her product, called Fo, resembles rivals in many respects: it lives in iMessage and WhatsApp, handles scheduling and life admin, and can place phone calls to businesses on a user's behalf. The distinguishing claim is architectural, not functional. Poddar and investor Vinod Khosla argue that Wajo has designed its stack for trust from the first line of code, a posture they believe matters more than feature velocity when an agent holds payment credentials and calendar access.

Khosla, whose firm has backed the startup alongside Google vice-president Jeff Dean and early-stage investor Gokul Rajaram, framed the competition in blunt terms. Large platforms built on advertising cannot credibly promise data hygiene, he suggested, because surveillance economics conflicts with user interest. Whether that argument resonates will depend on execution: trust is a claim until it survives scrutiny at scale.

What Fo Does Differently

Wajo's agent offers three capabilities that, taken together, set it apart from most current offerings. First, it can generate a virtual credit card for each transaction, masking the user's real payment details from merchants. The company has applied for a patent covering this system, which aims to reduce both fraud exposure and the data trail a user leaves across e-commerce sites. Second, Fo can escalate a task to a human contractor when automation fails or when a situation requires judgement the model cannot reliably provide. Third, the agent maintains its own email address and can correspond with businesses or individuals, acting as a buffer between the user and external parties.

In practice, this means Fo can book a restaurant, pay for a subscription, or reschedule a flight without the user handing credentials directly to a merchant. When a site blocks automated agents, Fo notifies the user or creates a group conversation that includes the business, allowing manual verification without breaking the workflow. The system is live in 107 countries, Wajo confirmed, and usage has grown tenfold since the late-September launch, though the company declined to share absolute user numbers or the size of the funding round.

Early Friction Points

Fo's calling feature, still in rollout, has surfaced questions that will likely apply across the category. During testing, the agent successfully contacted an airline to inquire about upgrade availability. A second test, a call to remind a family member to feed pets, went less smoothly, and the disclosure that an AI was placing the call was unclear. As more agents gain voice capability, the industry will need to settle on norms for identification, consent, and the boundaries of acceptable delegation. Wajo has said it will introduce a trusted-contact list, allowing users to specify who may receive agent calls. Recipients can also tell Fo not to call again, a preference the system records.

The design choice reflects a broader tension. Agents promise to collapse friction in daily tasks, but that friction often exists for good reason: to confirm identity, intent, or authority. Removing it too aggressively risks harm; removing it too cautiously negates the value proposition. Wajo is betting that granular controls and transparent architecture will let it thread that gap, but the bet remains unproven.

Poddar's Path from Gemini to Fo

Poddar's route to founding Wajo began with frustration. At Google, she contributed to bringing Gemini to market and worked on safety systems for large models. The experience convinced her that technical depth alone does not produce useful consumer products. She had earlier been involved in building Facebook's first assistant, and the pattern she observed was that technology-led organisations often lag in product intuition, while product-led organisations underinvest in safety and robustness. Wajo, in her view, needed to solve both simultaneously, and the only way to do that was to start from scratch with architecture and incentives aligned.

She emphasised that agents cannot yet unlearn data once ingested. If a system gains access to sensitive information on day one, that information persists in training or retrieval pipelines indefinitely. This technical constraint, she argued, makes early design choices about data handling irreversible. Wajo's response is to minimise what Fo sees in the first place: the agent does not store credit-card numbers, does not index private messages, and routes tasks through ephemeral channels wherever possible.

The Amazon Wedge

One claim Wajo has advanced publicly is that Fo can shop on Amazon without violating the platform's terms of service, even as Amazon has moved to block other agents. Poddar tweeted that Wajo's architecture complies with Amazon's agent policy, though she did not detail the technical mechanism. If accurate, this would represent a significant advantage: Amazon remains the highest-volume e-commerce destination in multiple regions, and agents that cannot operate there lose a large share of potential utility. At Opentechwire, we have tracked several startups in the agent category pivoting their compliance strategies after encountering platform resistance; Wajo's ability to maintain access will be a test of its architectural claims.

The broader question is whether platforms will tolerate agents at all. Amazon, Meta, and others have strong incentives to keep users inside their own interfaces, where behaviour can be tracked and monetised. An agent that intermediates transactions and communications disrupts that model. Wajo's success depends not only on user adoption but on whether it can sustain platform access as its volume grows.

What Trust Means in Practice

Khosla's thesis rests on the premise that users will choose privacy over convenience when the trade-off is made explicit. That premise is contested. Consumer behaviour over the past two decades suggests that most people accept surveillance in exchange for free or subsidised services, even when alternatives exist. Wajo is not free: the company has not disclosed pricing, but the infrastructure required to support virtual cards, human task delegation, and encrypted communication implies a cost structure incompatible with ad-supported distribution.

The startup's challenge is therefore to identify and capture the subset of users willing to pay for opacity. That market exists, but it is smaller and harder to reach than the mass market, and it demands that the product work reliably from the outset. A single data breach, a misrouted payment, or a poorly handled phone call could undo the trust positioning entirely. Wajo has built safeguards: virtual cards limit exposure, the trusted-contact list constrains calling, and the company has committed to recording user preferences about agent behaviour. Whether those safeguards suffice will become clear only under load.

The Multi-User Future

Wajo has indicated it will explore how Fo operates in social contexts, where multiple users' agents might interact to coordinate plans, split costs, or negotiate schedules. This is uncharted territory. Current agents are single-player: they act on behalf of one person, with that person's goals and constraints. Multi-agent coordination introduces game theory, conflicting preferences, and the risk of emergent behaviour that no individual user intended. Poddar has said privacy will remain central to this work, but the mechanics remain undefined.

If Wajo can make multi-user coordination work without leaking information between parties, it would open use cases that current agents cannot address: group travel planning, shared household management, or collaborative purchasing. It would also create new attack surfaces and new opportunities for misuse. The technical and ethical complexity is high, and the margin for error is narrow.

The Bigger Pattern

Wajo is one of at least a dozen well-funded entrants in the personal-agent category to launch in the past three months. The pace of entry reflects both the maturity of underlying models and the narrowing window for differentiation. As capabilities converge, companies are competing on positioning: trust, speed, platform integration, or vertical focus. Wajo has chosen trust, a defensible position if the architecture holds and if the market values it. But trust is expensive to build and easy to lose, and the competitive pressure to move faster, add features, and cut costs will test the company's discipline.

At Opentechwire, we have followed the funding rounds across this category and noted a pattern: investors are writing larger cheques at earlier stages than in previous cycles, betting that the window for category definition is short. Wajo's undisclosed round, with participation from Khosla, Dean, and Rajaram, fits that pattern. The capital gives the company runway to iterate, but it also raises expectations. The next six months will show whether Wajo's architecture can scale, whether users will pay for privacy, and whether platforms will let it operate. All three questions must resolve in Wajo's favour for the bet to pay off.

Read next
Startups

Tokyo Electron Eyes ¥1 Trillion Operating Profit as Testing Complexity Lifts Pricing Power

Kenji Watanabe · 5 min
Startups

Chinese Tech Groups Turn to Follow-On Deals to Fund AI Ambitions

Wei Zhang · 5 min
Startups

Lambda Eyes $14.5 Billion Valuation as Anthropic Deal Drives GPU Cloud Ambitions

Linh T. Pham · 5 min
Spot something wrong? Email corrections@opentechwire.com. We log every correction publicly.