The Claim Under Test
Every ranking of restaurant AI you will read this year is built on numbers that nobody outside the vendor has ever checked. Open five of them and you will find the same shape: a product claims 94% accuracy, or 96% order completion, or 86% autonomous handling, and the listicle prints it as though it were a measurement. It is not a measurement. It is a marketing assertion about the seller, published by the seller, with no methodology, no denominator, and no definition of the word being measured.
That would be a soft criticism in most industries. In this one it is not soft at all, because the claim has already been tested by a regulator with subpoena power, and it failed. In January 2025 the Securities and Exchange Commission entered an order finding that a publicly traded drive-thru voice AI company had made materially false and misleading statements about exactly this kind of number — while, on the SEC's findings, human order takers abroad processed the vast majority of orders placed through the product. That is not a hypothetical about vendor puffery. It is a federal administrative proceeding, with paragraph numbers, about a restaurant technology product.
So the claim under test in this article is narrow and specific: can an operator rely on any published performance figure in this category? Our answer, after checking every vendor site in the roster on 23 August 2026, is no — and the useful consequence is that you should stop trying. Rank on what you can verify from a browser and a contract, put the performance question into your RFP as a written commitment rather than a number you read on a homepage, and measure the thing yourself at your own sites, in your own lanes, with your own guests.
This piece sits inside a wider set of vertical rankings built on the same method; the cross-industry version, with the same refusals applied to general-purpose tools, is our guide to the top AI agents in 2026. What follows is the restaurant edition: what we scored, what we would not score, ten vendors in order, the constraint that decides whether any of it works, and the parts we could not verify.
How We Ranked, and What We Refused to Rank On
We scored eight attributes, every one of which you can re-check from a browser in under an hour. That constraint is the whole method. If a buyer cannot independently confirm a cell in our table, the cell does not belong in a ranking — it belongs in a sales deck.
What we scored — every attribute re-checkable by the reader
- Documented public integrations — named on the vendor's own site, not on a partner's
- Whether the vendor publicly publishes compliance documentation (SOC 2, PCI DSS, ISO 27001) and at what level of detail
- Pricing transparency — published amounts versus “contact sales”
- Whether the product is standalone or locked to a suite
- Ownership and corporate status from the public record — SEC filings, completed acquisitions, press releases
- Whether any independent evaluation of the product exists
- Whether the vendor discloses a human-in-the-loop rate for automated ordering
- Data residency, retention and DPA availability as published, not as promised in a call
We refused to score accuracy, order completion, automation rate, deflection, containment, labour hours saved, revenue lift and ROI.Not because they do not matter — they are the only things that matter operationally — but because every published figure in this market is self-reported by the seller, and there is no neutral party checking any of them. Printing a vendor's accuracy claim beside a competitor's in a comparison table implies a common measurement standard. There is no common standard. There is not even a common definition: one vendor's “automation rate” may count an order as automated when restaurant staff did not intervene, while a remote agent did.
That last distinction is not a hypothetical we invented for rhetorical effect. It is drawn word for word from a federal enforcement order, and it is the subject of the next section.
| The claim | Where it comes from | What we print instead |
|---|---|---|
| “60% of restaurants fail in the first year” | Parsa et al. (2005) found 59% cumulative failure over three years. The 60% claim is that three-year number reported as one year | About 26% fail in the first year, per the same study of 2,439 Columbus restaurants, 1996–1999 |
| “Restaurant turnover is 70–75%” | No public series produces it. BLS publishes no restaurant-only turnover rate at all | Summing BLS JOLTS monthly total separations for accommodation and food services gives roughly 65.3% for 2025 and 65.7% for 2024 — our arithmetic, from the linked series, including hotels |
| Any vendor accuracy, completion or automation rate | Self-published marketing. One such claim was the subject of an SEC enforcement order | The Intouch third-party measurement, with its methodology attached, and a written RFP question about human-in-the-loop rates |
| A missed-call or phone-abandonment revenue figure | The lead-magnet genre — one vendor in this roster ships a “Missed Call Revenue Calculator” on its product page | Your own call-detail records from your phone provider for the last 90 days, which cost nothing and are actually about you |
| “Toast Sous Chef lifted average order volume 6%” | Secondary coverage of earnings commentary; the product URL returns 404 on Toast's own site | Nothing. We could not verify the product exists on the vendor's own product pages, and we say so |
| “McDonald's new drive-thru AI ran a million orders at 90% accuracy” | A content-farm blog with no traceable source | McDonald's ended its IBM automated order-taking test, off in all restaurants by 26 July 2024, and is reported to be running a small new test |
What Happened the One Time a Regulator Audited the Numbers
On 14 January 2025 the SEC entered a settled order against Presto Automation Inc., in what is widely described as its first AI-washing enforcement action against a public company. The citation is In the Matter of Presto Automation Inc., Securities Act Release No. 11352, Exchange Act Release No. 102177, Administrative Proceeding File No. 3-22413. The findings concern statements about the company's flagship drive-thru voice product made in Commission filings and public statements from November 2021 through May 2023.
The marketing side of the story is familiar to anyone who has sat through a vendor demo. A January 2022 press release claimed the product delivered “over 94% accuracy even in noisy environments”. Investor materials claimed 95%–99% “automated order completion.” Those are precisely the numbers a competing listicle would have reprinted in a comparison table.
What the order found is the part that should change how you buy.
Presto Voice units powered by Presto's proprietary AI speech recognition technology lacked the capability to take orders on their own and required substantial human involvement.
— SEC, In the Matter of Presto Automation Inc., Securities Act Release No. 11352 (14 January 2025), ¶3
Presto hired, trained, and supervised human order takers located abroad (primarily in the Philippines and India), who processed the vast majority of drive-thru orders placed through Presto Voice.
— SEC, In the Matter of Presto Automation Inc., Securities Act Release No. 11352 (14 January 2025), ¶3
The order also records how the company's own metric was constructed. The completion rates it cited referred, in the order's words, to rates at which drive-thru orders were completed without restaurant staffinvolvement — but not without any human involvement at all. That is the definitional trapdoor. A number can be literally accurate and still describe the opposite of what a buyer hears.
And the internal record quoted by the SEC shows the company understood the gap. An internal message quoted in the order, dated January 2023, describes the practice of telling investors the AI was running 95%+ accuracy without disclosing that the AI was doing none of the work and all orders were processed by humans. An October 2022 message quoted in the same paragraph objects to publishing an automation rate to customers because it infers no supervision, which was not true. Messages from January 2022 quoted at paragraph 27 put the mechanism plainly: with humans in the loop, accuracy is not a major concern, and the figure can even reach 95% or more with humans. We attribute these to the SEC's order rather than to any named individual, because the order does not name them.
By the time the company disclosed the true picture, the numbers had inverted. Its 17 November 2023 prospectus supplement stated that over 70% of orders taken by the product required human agent intervention. A 14 December 2023 Form 8-K disclosed human intervention on 100% of orders at the substantial majority of locations running the original version. Those are the same product, the same period, and a completely different story from the press releases.
1. Presto consented to the order without admitting or denying the findings. Nobody admitted anything, and it is wrong to write that they did.
2. The remedy was a cease-and-desist order with no civil penalty; the Commission stated it considered the respondent's financial condition. Presto was not fined.
3.The findings run against Presto only, and specifically against its failure to disclose that it relied on a third party's speech technology — a supplier Presto later identified in its own October 2023 Form 10-K. The order does not find that the supplier misled anyone. We therefore do not name the supplier in connection with this proceeding, and neither should anyone else.
One more precision point, because it is the error most likely to be repeated. Presto Automation Inc. is not Presto Phoenix Inc.The original company was delisted from Nasdaq in September 2024, defaulted on its loan, and its lender foreclosed; the assets were sold on 3 December 2024 to a venture investor group led by Remus Capital with $18 million of new capital, and the product now trades under a new entity whose site reads © 2026 Presto Phoenix Inc. The SEC order concerns the old public company. Attaching it to the current entity as though they were one continuous business would be exactly the kind of sloppiness this article exists to refuse — which is also why we do not rank Presto Phoenix in the ten. The entity that made the claims no longer exists, and the current entity publishes no more verifiable information than anyone else in the roster.
Use the order the way a regulator would want it used: as the one documented instance of what happens when someone actually audits a published AI performance metric in this industry. It found the metric did not mean what buyers thought it meant. That is why we score only what you can check.
The Only Third-Party Measurement That Exists
No independent benchmark of these products exists — but restaurants are unusually lucky, because one genuine third-party measurement of the modality does. Intouch Insight published its 25th Annual Drive-Thru Study with QSR Magazine on 1 October 2025. The methodology is public: fieldwork in June and July 2025, across the United States at varying days and times, 165 mystery shops per brand across 13 quick-service brands, plus 120 AI-enabled orders evaluated across three chains testing voice-AI ordering.
| Measure | AI-enabled orders | Study average |
|---|---|---|
| Order accuracy | 83% | 87% |
| Order accuracy when staff assisted the AI | 95% | — |
| Guest had to repeat themselves | 34% of orders | 22% |
| Service time | 3:53 | 4:15 (AI roughly 21 seconds faster) |
| Satisfaction | 97% | 91% |
| Friendliness | 72% | 78% |
Errors on AI-enabled orders were, in the study's own words, most frequently attributed to order customization. Hold onto that sentence — it reappears in the allergen section, because allergen substitutions are order customisations, and it reappears in the human-in-the-loop table, because it tells you exactly where to put the escalation trigger.
Now put the two independent findings side by side, because their convergence is the strongest evidence in this entire category. A federal regulator, looking at internal documents, found a vendor concealing that humans were doing the work. A mystery-shop study, looking only at outcomes in the lane, found that the good accuracy number appears when a human steps in. Neither knew about the other. They point at the same variable: the undisclosed human. And not one vendor in this roster publishes a human-in-the-loop rate.
The speed finding deserves a fair hearing too, because the honest read is not one-sided. Roughly 21 seconds per car is a real operational gain, and satisfaction scored higher on AI-enabled orders than the study average. If your binding constraint is throughput at peak and your order mix is simple, that is a legitimate reason to run a pilot. If your order mix is heavy on modifiers — build-your-own formats, allergy-sensitive menus, complex customisation — the measured error concentrates precisely in your traffic, and the same study is a reason for caution. Read it as a map of where the technology is strong and weak, not as a verdict.
The Comparison Table
Every cell below is either a citation you can open or the literal words “not publicly disclosed.”There is no accuracy column, no ROI column and no rating out of five, because none of those could be filled honestly. All entries were checked on 23 August 2026 against the vendor's own pages and the public corporate record.
| Vendor (checked 2026-08-23) | What it actually is | Published pricing | Published compliance | Named integrations on the vendor's own site | Ownership of record |
|---|---|---|---|---|---|
| 1. Slang.ai | Inbound phone agent for reservations and guest questions — transactional | Yes, to the dollar: Core $399 per location per month; Premium $599; Enterprise custom (slang.ai/pricing) | Displays a SOC 2 badge linking to a Drata trust centre; the trust centre itself did not resolve for us, so we do not assert Type II | OpenTable, SevenRooms, Tripleseat, Yelp, Fishbowl. Resy and Toast are not listed | Not stated on the site — legal entity not publicly disclosed |
| 2. ConverseNow | Voice ordering agent for drive-thru and phone — transactional | Not publicly disclosed | Not publicly disclosed — no trust page located | Brink POS, Fiserv, Focus, ItsaCheckmate, NCR Aloha, Olo, PAR, Qu, Xpient, plus Deliverect (April 2026) | ConverseNow Technologies Inc., independent; acquired Valyant AI 10 July 2024 |
| 3. Olo | Ordering, payments and guest-data infrastructure that agents plug into — not itself an agent | Not publicly disclosed | PCI DSS v4.0.1, SOC 1 Type 2, SOC 2 Type 2 (trust.olo.com) — the best-documented in this roster | A large integration catalogue; DPA, residency and retention terms sit behind an access-request gate | Thoma Bravo portfolio company since 12 September 2025; delisted from the NYSE |
| 4. OpenTable | Reservation and table management with classic automation and a demand network — no AI agent named on the plans page | Yes: Basic $149, Core $299, Pro $499 per month, plus $1–$1.50 per network cover; one-year auto-renewing contract | Not publicly disclosed on the pages we checked | POS integration is a listed capability; specific POS names are not enumerated on the plans page | Not verified this session — we do not assert a parent company |
| 5. SoundHound AI | Drive-thru, kiosk, phone and in-car voice ordering plus an employee copilot — transactional at the order layer | Not publicly disclosed | Not publicly disclosed — the trust-centre URL returned 404 for us | None named on the restaurant page; named customers include White Castle | Nasdaq: SOUN. Merger with LivePerson pending as of 23 August 2026 — regulatory conditions satisfied, stockholder vote outstanding |
| 6. Nory | Agentic operations suite: scheduling, ordering, payroll and reviews assistants — mixed autonomy | Not publicly disclosed | Not publicly disclosed | An integrations ecosystem is referenced; no POS is named | Legal entity not stated on the site; operating in Europe and North America |
| 7. Popmenu | AI phone answering that deflects and hands off by sending a link — not a transactional order-taker | Not publicly disclosed — a pricing link exists, no amounts published | Displays SOC 2 and PCI DSS badges; no trust centre or report type disclosed | Its own website, ordering, loyalty and marketing stack; no third-party POS names published on the page | Popmenu, Inc., Atlanta, Georgia |
| 8. Restaurant365 | Back-of-house platform — accounting, inventory, workforce, payroll — with R365 AI features, mostly copilot plus AI Scheduling | Not publicly disclosed | Not publicly disclosed | Not named on the pages we checked | Not stated on the site; no acquisition activity claimed by the vendor |
| 9. Toast | Restaurant platform with documented AI features — benchmarking, a marketing assistant and intelligent chat support | Not publicly disclosed for software; hardware promotions are advertised | Not publicly disclosed on the pages we checked | Locked to Toast POS by design | Toast, Inc., Boston — public company |
| 10. Hi Auto | Drive-thru AI Order Taker — transactional | Not publicly disclosed | Not publicly disclosed | States it integrates with store platforms; none named | Legal entity not stated on the site; footer still reads © 2025 |
Three patterns jump out of that table and they are more useful than any ordering we could impose on it. First, published compliance documentation is nearly absent from this category. Exactly one vendor publishes a real trust centre with named report types. Two display badges without a reachable report. Seven publish nothing we could verify. For an industry that processes card payments and, increasingly, voice recordings, that is a finding in itself.
Second, published pricing is rarer still. Two vendors publish amounts. In a market selling to operators who budget to the penny per cover, that asymmetry is a choice, and it is a choice worth pricing into your evaluation time: every gated quote is a sales cycle you are paying for in calendar days.
Third, and most importantly, not one vendor discloses a human-in-the-loop rate.Nobody publishes what share of orders is completed with no human — not restaurant staff, not a remote agent — touching them. After the SEC order and the Intouch data, that is the number a serious buyer should demand in writing. It is also the easiest thing in the world to ask for and the hardest thing to fake in a contract.
The Ten, in Order
The ordering below reflects verifiability, not performance.A vendor that publishes its price, names its integrations and documents its compliance ranks above one that publishes nothing — not because its software is better, but because you can make an informed decision about it and hold it to what it said. That is the only ranking anyone can defend right now.
1. Slang.ai — the pricing-transparency winner
What it does: answers inbound restaurant calls around the clock, books and manages reservations, answers guest questions, routes VIP calls, and raises alerts for private dining enquiries, complaints and lost items.
What is verifiable:published per-location pricing — Core at $399 per location per month and Premium at $599, with an Enterprise tier quoted custom. Premium adds custom branding, reservation cross-selling, real-time alerts, bilingual Spanish support and a smart inbox. Named integrations: OpenTable, SevenRooms, Tripleseat, Yelp and Fishbowl. À la carte add-ons for private events and bilingual support. No per-call or overage charges disclosed.
What is not disclosed:the legal entity is not stated on the site. A SOC 2 badge in the footer links to a Drata trust centre, but the trust centre did not resolve for us — so we record “displays a SOC 2 badge” and not “holds SOC 2 Type II.” No DPA, residency or retention commitments are published. Resy and Toast are not on the integration list; do not assume them.
Who it fits: full-service and reservation-led restaurants where the phone is a booking channel and the pain is unanswered calls during service. Who it does not:quick-service drive-thru operators — this is not an order-capture product for the lane.
2. ConverseNow — the best-documented integration list in the roster
What it does: voice ordering for drive-thru and phone, designed to capture the order rather than hand the guest a link.
What is verifiable:the most substantial integration list any vendor here publishes on its own site — Brink POS, Fiserv, Focus, ItsaCheckmate, NCR Aloha, Olo, PAR, Qu and Xpient — plus a Deliverect partnership announced 16 April 2026 that routes voice orders into unified order management alongside third-party delivery and first-party digital. Named customers include Blake's Lotaburger, Denny's, Domino's Pizza, Fazoli's, Hardee's, Jet's Pizza and Wingstop. Corporate: ConverseNow Technologies Inc., independent, and the acquirer of Valyant AI in a deal announced 10 July 2024.
What is not disclosed:pricing. Compliance — we located no trust page. Funding figures circulating around $28.8 million across three rounds come from private databases and press coverage rather than a public filing, so treat them as indicative.
Who it fits: multi-unit quick-service operators who already run one of the named POS platforms and want the voice layer to survive a POS migration. Who it does not: single-site independents, and anyone who needs a compliance report before signature.
3. Olo — infrastructure, not an agent, and the compliance benchmark
What it does:online ordering, delivery dispatch, channel aggregation, catering, loyalty, payments, guest data and sentiment — the plumbing that ordering agents plug into.
What is verifiable:the best-documented compliance posture in this roster, published openly: PCI DSS v4.0.1, SOC 1 Type 2 and SOC 2 Type 2. Ownership is a matter of public record — Thoma Bravo completed its all-cash acquisition on 12 September 2025 at $10.25 per share, roughly $2.0 billion in equity value, with stockholders approving at a special meeting on 9 September 2025 and the stock ceasing to trade and being delisted from the NYSE.
What is not disclosed: pricing. DPA availability, data residency and retention terms sit behind an access-request gate. And critically: no named AI agent product appears on the site. We rank Olo honestly as infrastructure rather than as an agent.
Who it fits: enterprise brands who need the ordering and guest-data layer to be auditable before anything agentic is layered on top. Who it does not: anyone shopping for an agent — that is not what this is. One practical note: any article still describing Olo as publicly traded is stale, and that is a fast way to date a competing listicle.
4. OpenTable — classic automation, priced to the dollar
What it does:reservation and table management — smart table assignment, access rules, waitlist, automated reservation messaging, automated guest tags, guest profiles and pre-shift reporting — plus a consumer demand network.
What is verifiable:the most complete published price list in the category. Basic at $149 per month, Core at $299, Pro at $499. Per-network-cover fees of $1.50 on Basic after a free 30 days, and $1 on Core and Pro. Reservations from your own website cost $0.25 per cover or $49 per month flat on Basic and are included on Core and Pro. Prepaid experiences and ticketing carry a 2% service fee. The standard contract is one year, auto-renewing annually, with 30 days' notice to stop renewal. Cover fees apply only to seated diners, with no charge for no-shows, cancellations, phone reservations or walk-ins on Core and Pro.
What is not disclosed: no AI agent is named on the plans page, and we classify the product as automation and a demand network rather than an autonomous agent. Specific POS integrations are not enumerated there. We did not verify its parent company this session and therefore do not assert one.
Who it fits: reservation-led restaurants that want a known unit cost. Who it does not: operators expecting conversational autonomy from this line item. It is on the list because operators genuinely shortlist it against phone agents, and the honest thing is to say what it is.
5. SoundHound AI — the deepest public record, and a pending merger
What it does:the broadest restaurant voice product line here — Dynamic Drive-Thru, Smart Lane, Dynamic Kiosk, Smart Ordering across phone, SMS and app, in-car food ordering, an employee assistant and voice analytics.
What is verifiable:more than any private vendor can offer, because it is a reporting company. SOUN on Nasdaq, Commission File No. 001-40193, CIK 1840856, headquartered in Santa Clara, actively filing with a 10-Q filed 10 August 2026. It acquired SYNQ3 Restaurant Solutions in a deal announced 7 December 2023. Named restaurant customers include White Castle, Blue Square Pizza and Detroit's Original Chicken Shack.
The status point that matters: the LivePerson transaction is pending, not closed. Per an 8-K/425 with an event date of 20 July 2026, the final foreign investment clearance arrived that day, satisfying all regulatory approval conditions — but the filing states the mergers remain subject to other closing conditions including LivePerson stockholder approval. As of 23 August 2026 it had not closed. Anyone writing that SoundHound acquired LivePerson is ahead of the record.
What is not disclosed:pricing. Compliance — the trust-centre URL returned 404 for us, so we assert no SOC 2. No POS integrations are named on the restaurant page. The site publishes an 11% revenue increase, 85% faster service times and a 93% accuracy rate among clients; all three are vendor claims and none is a measurement.
Who it fits: larger operators who want a counterparty whose finances and corporate events are on the public record. Who it does not:anyone who cannot tolerate integration ambiguity or ownership change mid-contract — put a change-of-control clause in front of counsel.
6. Nory — the clearest agent decomposition, and the biggest blast radius
What it does: self-describes as an agentic AI restaurant operating system, with four named assistants: a Scheduling Assistant that builds schedules against forecast, budget and compliance requirements; an Ordering Assistant that checks inventory against forecast demand and creates and sends supplier purchase orders; a Payroll Assistant that builds pay runs from real shifts and timecards; and a Customer Reviews Assistant that recommends specific fixes.
What is verifiable:the decomposition itself, which is unusually honest — autonomy is explicitly mixed. Ordering and Payroll take actions; Reviews recommends. The company states it operates across Europe and North America, including the US.
What is not disclosed: pricing, legal entity, compliance documentation, and any named POS integration. A published forecast accuracy figure of up to 97–98% is a vendor claim and we do not treat it as measurement.
Who it fits: multi-unit operators whose pain is back-of-house labour and ordering rather than guest-facing voice. Who it does not:anyone unprepared to govern autonomous purchase orders — an agent that sends supplier POs is the single highest blast-radius autonomous action in this roster and belongs behind a value threshold and an approval queue on day one.
7. Popmenu — deflection and handoff, and one thing to refuse
What it does: AI phone answering in a custom voice, sending the guest a reservation or ordering link during the call, answering common questions about hours, location, parking and allergens, and reporting call outcomes and call volume by hour in an owner app. It sits inside a wider marketing stack: website, interactive menus, reputation management, online ordering, order aggregation, loyalty and a branded mobile app.
What is verifiable: the product classification, which the comparison table should not blur. This is a deflection-and-handoff agent, not a transactional one— it sends links rather than capturing the order or the booking itself. That is a materially different product from a voice order-taker, with a materially different failure profile. The entity is Popmenu, Inc. of Atlanta, Georgia. SOC 2 and PCI DSS badges appear in the footer.
What is not disclosed:pricing amounts. Report type for the compliance badges — no trust centre link, so we say “displays badges” and stop there.
What we refuse:the product page hosts a “Missed Call Revenue Calculator.” That genre — missed-call and phone-abandonment revenue estimates — is exactly the kind of unsourced figure this article exists to reject, and we do not print any output from it. Its case-study revenue figures are likewise unexplained and un-methodologised, so we do not present them as outcomes. Use your own call-detail records instead; your phone provider already has them.
Who it fits: independents and small groups whose real problem is that nobody answers the phone at 7pm. Who it does not: operators who need the agent to complete the transaction.
8. Restaurant365 — back of house, with one wage-hour flag
What it does: accounting with AP automation, banking, fixed assets, budgeting and reporting; inventory and purchasing with recipes, prep, receiving, cash management and commissary; workforce management with scheduling, sales forecasting, training, time and attendance, task management and tip automation; and payroll and HR.
What is verifiable:the module list and the named AI features. R365 AI is described as an intelligence engine built on the full restaurant P&L — a vendor characterisation, not ours — with an AI Advisor in early access through a programme called Chef's Table, AI Scheduling that generates optimised schedules automatically, and AI Dashboards for inventory monitoring.
What is not disclosed: pricing, compliance documentation and named POS integrations.
The flag worth raising: tip automation. With the 2021 dual-jobs rule vacated and the pre-2021 regulation restored, how any tool classifies tipped and supporting duties is a legal question wearing a software costume. If you run tip automation, someone with wage-hour training should own the duty classification configuration and version it. See the wage-hour section below.
Who it fits: multi-unit operators consolidating back-office systems. Who it does not:anyone shopping for guest-facing voice — this is mostly copilot and analytics with one autonomous action.
9. Toast — a large platform whose flagship agent we could not verify
What it does: a restaurant platform combining software, payments, financial technology and hardware, which its investor materials describe as including agentic AI.
What is verifiable on Toast's own site:three AI features — Toast Benchmarking, an AI-powered marketing assistant, and intelligent chat support inside Toast Web and Toast Now. The entity is Toast, Inc. of Boston, a public company.
Two disclosure findings we think an operator should know.First, the page where Toast's AI URL resolves states that it was last updated on 12 December 2024 — roughly twenty months stale as of our check. Second, its footer carries the disclaimer that Toast AI products may utilise technology provided by third party service providers. That is a candid disclosure, and it is directly relevant both to the CIPA capability question below and to the disclosure failure at the centre of the SEC order.
What we could not verify: a widely referenced voice agent called Sous Chef. The product URL returns 404 on Toast's own site, and the ~6% average order volume lift attributed to it appears only in secondary coverage of earnings commentary. We do not state that the product exists, we do not print the figure, and we do not rank Toast on either. Reporting that gap is precisely the job.
Who it fits: operators already committed to Toast POS, for whom the AI features are an increment rather than a decision. Who it does not: anyone buying the agent rather than the platform, or anyone unwilling to be locked to one POS.
10. Hi Auto — a real drive-thru product with almost nothing published
What it does:an AI Order Taker for the drive-thru lane, with named customers including Bojangles and Lee's Famous Recipe Chicken, and vendor statements of 200+ franchisees worldwide across roughly a thousand stores.
What is verifiable: the product exists, the site is live, and the named customers are stated on it.
What is not disclosed — and this is why it ranks tenth:pricing, compliance documentation, legal entity, and any named POS or store-platform integration beyond a general statement that it integrates with store platforms. Published figures of over 93% completion and 96% accuracy at scale are vendor claims, and they run in the opposite direction from the only third-party measurement of the category. Human-agent fallback is not disclosed — the site does not state whether humans assist or take over. A footer still reading © 2025 is a small housekeeping observation, not evidence of anything.
Who it fits: quick-service operators running a lane pilot who are prepared to do their own measurement and to negotiate every term from a blank page. Who it does not: anyone whose procurement process requires published compliance artefacts, and anyone unwilling to make the human-in-the-loop question a written contractual commitment.
The Binding Constraint: Voice Capture Consent
The binding constraint for restaurant AI is not accuracy. It is that a voice agent creates a recording, and in several states a recording of a voice is a regulated biometric identifier or a two-party-consent problem. The drive-thru speaker box is plausibly the highest-volume consent surface in American retail, and almost nobody treats it as one.
Start with Illinois, because the statute is unusually literal. Under 740 ILCS 14/10, a “biometric identifier” means “a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry.” Voiceprint is right there in the enumerated list. Section 15(b) requires three things beforecollection: written notice that a biometric identifier is being collected or stored, written notice of the specific purpose and length of term, and a written release executed by the subject. Section 15(a) requires a published retention schedule and destruction guidelines — destruction when the initial purpose is satisfied or within three years of the individual's last interaction, whichever comes first. Section 20 provides liquidated damages of $1,000 or actual damages for negligent violations, $5,000 or actual damages for intentional or reckless ones, plus attorneys' fees, expert witness fees and litigation expenses.
One status point people get backwards. The 2024 amendment — Public Act 103-0769, effective 2 August 2024 — added that repeated collection of the same biometric identifier from the same person by the same method is a single violation for which the person is entitled to “at most, one recovery,” with a parallel limit for repeated disclosures. That legislatively overrides the per-scan accrual theory. It caps the number of recoveries. It does not reduce the $1,000 and $5,000 figures, which stand exactly as written. Secondary reporting suggests the Seventh Circuit held in April 2026 that the damages amendment is remedial rather than substantive and therefore applies retroactively to pending cases; we did not read that opinion ourselves and flag it as secondary.
There is a newer development operators should track without overstating. Nine coordinated BIPA voiceprint class actions were filed in the Northern District of Illinois in May 2026 against a group of large technology companies, alleging that voiceprints were collected for AI voice-model training without BIPA disclosures, consent or retention safeguards. That account comes from the plaintiffs' own law firm and consists of allegations, not findings, and we attribute it as such. Its relevance here is structural rather than factual: it establishes that the training-data useof captured voice is now itself a theory of liability — and that is exactly what a restaurant voice vendor's standard contract usually permits.
Now California, where the intuition of most operators is precisely inverted. Penal Code § 632 bars intentionally recording a “confidential communication” without the consent of all parties — but the statute's own definition excludes a communication made “in any other circumstance in which the parties to the communication may reasonably expect that the communication may be overheard or recorded.” An outdoor drive-thru speaker, with cars queued behind and a menu board in the open air, is a strong candidate for that exclusion. An inbound reservation call to a restaurant is not. So the phone line carries more CIPA risk than the lane, which is the opposite of how most operators rank the two. We present that as analysis, not settled law, and you should have counsel apply it to your states.
Section 631 is the provision that pulls the vendor into your problem. It reaches anyone who reads or attempts to read or learn the contents of a message in transit without authorisation, and equally anyone who “aids, agrees with, employs, or conspires with” another to do so, with penalties up to $2,500 for a first offence and up to $10,000 with a prior conviction under the related sections. In Ambriz v. Google, LLC, No. 3:23-cv-05437-RFL (N.D. Cal., 10 February 2025), the court denied a motion to dismiss a § 631(a) claim on a theory commentators have called a capability test: a cloud contact-centre AI provider could qualify as a third party rather than a mere extension of the business because it had the capability to use call data for its own purposes, including model training and product improvement, regardless of whether it actually did so. A denied motion to dismiss is not a holding of liability, and the theory faces standing pressure; present both sides in your own risk memo.
Finally, outbound calling. The FCC's Declaratory Ruling FCC 24-17 in CG Docket No. 23-362, adopted 2 February 2024 and released 8 February 2024, confirms that the TCPA's restrictions on an “artificial or prerecorded voice” encompass current AI technologies that generate human voices, so such calls require the prior express consent of the called party absent an emergency purpose or exemption — and prior express written consent for marketing. The ruling expressly declines to carve out technologies that purport to provide the equivalent of a live agent. Separately, 47 U.S.C. § 227(d)(3) requires artificial or prerecorded messages to identify the business at the start and provide a telephone number or address.
Do not let anyone tell you the TCPA got easier. Insurance Marketing Coalition v. FCC(11th Cir., 24 January 2025) vacated only Part III.D of a 2023 FCC order — the one-to-one consent provision — and the court's own footnote states that the 2012 Order is not at issue. One narrow consent provision was vacated. The written-consent regime and the artificial-voice classification both stand, and an AI voice agent placing outbound calls sits squarely inside them. Inverting that would be advice an operator could act on and get sued for. Note the scope discipline as well: this governs your waitlist callbacks, reservation confirmations and marketing calls. An inbound call the guest chose to place is a different analysis.
| Channel | The exposure that actually attaches | What it turns on | Practical control |
|---|---|---|---|
| Outdoor drive-thru lane | Illinois BIPA if a voiceprint is created or stored; state wiretap law generally weaker here | Whether the vendor derives or retains any voice template, versus transcribing and discarding audio | Contractually forbid voiceprint derivation and retention; post signage; keep an Illinois-specific configuration |
| Inbound reservation or ordering phone line | California CIPA §§ 631 and 632 — the strongest exposure in the stack, and the one most operators underrate | Whether the call is a “confidential communication” and whether the vendor is a third party with the capability to use call data for its own purposes | Two-party consent disclosure at answer; strike the model-training clause; require written deletion schedules |
| Outbound callback, confirmation or marketing call using a synthetic voice | TCPA — FCC 24-17 classifies AI-generated voices as “artificial” voices | Prior express consent, and prior express written consent for marketing; identification and opt-out obligations | Consent capture at the point of collection with retained proof; identify the business at the start of the message; honour opt-outs in the same system |
| Kiosk or app with voice input | BIPA if voice is captured; ADA effective-communication expectations if voice is the only path | Whether an equivalent non-voice path exists and works | Always ship a non-voice equivalent; do not treat a better voice model as an accessibility remedy |
| Any channel, any state, where the vendor trains on your guests' audio | The clause that converts a service provider into a third party under the CIPA capability theory | The words “to improve our services and models” in the vendor's DPA or terms | Redline it before signature. This is the single highest-leverage sentence in the contract |
Wage-Hour, Allergens and Accessibility
Three constraints follow the consent problem, and each one has a status detail that is routinely reported wrong.
The 80/20 rule is vacated — not stayed, not enjoined, not merely unenforced. In Restaurant Law Center; Texas Restaurant Association v. U.S. Department of Labor, No. 23-50562, the Fifth Circuit issued its opinion on 23 August 2024, holding that the 2021 Dual Jobs Final Rule “fails under the Administrative Procedure Act twice over. Because the Final Rule is contrary to the Fair Labor Standards Act's clear statutory text, it is not in accordance with law. And because it imposes a line-drawing regime that Congress did not countenance, it is arbitrary and capricious.” The disposition, from the body of the opinion, reversed the district court, rendered summary judgment for the associations, and vacated the Final Rule; the panel declined remand without vacatur because the rule suffered from a fundamental substantive defect the Department could not rectify.
Then keep the dates straight, because merging them is the common error. The opinion issued 23 August 2024. The Department of Labor's subsequent Federal Register notice refers to the court's order vacating the regulatory text as issuing on 29 October 2024. DOL then removed the corresponding text from the Code of Federal Regulations and reinstated the pre-2021 regulation through a final rule that was published and effective on 17 December 2024, described as a technical amendment accounting for changes in the law that had already occurred. Three dates, three different events. What is gone: the 20-percent-of-workweek limit on directly supporting work and the 30-minute continuous limit. What governs: the restored pre-2021 dual-jobs regulation.
Allergen accuracy is the un-delegatable risk, and the data tells you exactly where it lives. The Intouch study found that AI order errors were most frequently attributed to order customization. Allergen substitutions areorder customisations. That is the empirical link between the accuracy data and the safety risk, and it needs no additional statistic. Meanwhile, at least one vendor in this roster advertises on its own product page that its AI phone agent answers questions about hours, location, parking, allergens and more — putting an allergen answer in the mouth of an automated system whose contract will disclaim responsibility for it.
The defensible boundary, stated as analysis: an agent may read a documented menu attribute back to a guest; a human must own any answer about whether a dish is safe for a specific person.The liability is not delegable to a vendor whose terms exclude it, and the escalation trigger should be a hard-coded phrase list rather than a model judgement call. We were unable to verify current FDA Food Code text this session — every URL we tried returned 404 — so we state no edition year, adoption count or section number, and you should confirm the specifics with your food-safety lead and counsel.
Accessibility is the constraint nobody budgets for. The Department of Justice's web accessibility guidance of 18 March 2022 states that the Department has consistently taken the position that the ADA's requirements apply to all the goods, services, privileges or activities offered by public accommodations, including those offered on the web, and that businesses must ensure the programs, services and goods they provide to the public are accessible to people with disabilities. Status precision: that page carries a notice that it does not reflect requirements published for state and local governments in April 2024 — that 2024 rule is a Title II rule. There is no Title III technical web or kiosk standard, so do not claim a private restaurant must meet a specific technical standard by regulation; Title III obligations run from the statute and case law.
The operational point is simpler than the legal one. A voice-only drive-thru or phone channel with no equivalent alternative is the accessibility failure mode for Deaf and hard-of-hearing guests, and the mitigation is an equivalent non-voice path — a kiosk, an app, a text channel, a staffed lane — not a better voice model. Build the alternative path into the pilot scope, not into the remediation budget.
A Worked Example: 14 Units, Two Channels
This is an illustrative scenario, not a client result. We have deliberately not attached a real customer outcome to it, because an article that refuses unsourceable industry statistics and then asserts an unverifiable client number has destroyed its own standing. Every figure below is either something you can measure at your own sites in a fortnight, or a published price from the table above.
Consider a 14-unit fast-casual group: eight units with drive-thru lanes, fourteen taking phone orders, one central kitchen, roughly 65% of orders carrying at least one modifier. The operator has two candidate channels and a board that wants an answer about AI this quarter.
Step 1 — Establish a baseline from data you already own (2 weeks, no vendor involved)
Pull 90 days of call-detail records from your phone provider: total inbound calls per site per hour, answered, unanswered, average ring time. Pull the same period from the POS: order count by channel, modifier rate, void and comp rate, and remake rate if you capture it. Have shift leads log order errors at the window for two weeks using a one-line paper tally. That baseline costs nothing and it is about you— which is more than can be said for any benchmark a vendor will hand you. Notice what we did not do: we did not use a missed-call revenue calculator, because those figures have no methodology and we refuse them.
Step 2 — Pick the channel where the published evidence is least unfavourable
With a 65% modifier rate, the drive-thru lane is the harder case, because the one third-party measurement found AI errors concentrated in order customization. The phone line is the easier case: reservation and simple-order handling, where the failure mode is a dropped call rather than a wrong allergen. So the pilot goes to the phone first. If the phone channel is genuinely reservation-led, a published-price product at $399 per location per month is a known quantity: fourteen locations is $5,586 per month, or $67,032 a year at list before negotiation. That is arithmetic from a published price, not an estimate— and it is the number to compare against the labour hours the baseline says are currently going into call handling.
Step 3 — Write the two questions no vendor answers voluntarily
First: what percentage of orders at comparable sites in the last 90 days were completed without any human — restaurant staff or remote agent — touching them, and how is that measured? Second: does your agreement permit you to use our guests' audio or transcripts to train or improve your models, and will you delete on a written schedule? The first question is the SEC order translated into procurement. The second is the CIPA capability theory translated into a redline. Both belong in the contract, not in the sales call.
Step 4 — Run four sites, not fourteen, and instrument two numbers
Track the escalation-to-staff rate and the guest repeat rate per site per daypart. Report both next to any accuracy figure, never instead of it. If the escalation rate is high and accuracy looks good, you have not automated the channel — you have moved the work and added a subscription. That is the exact failure the SEC order describes, discovered on your own data, for the cost of a pilot.
The pattern generalises beyond ordering. Once the guest-facing channel is instrumented, the same discipline applies to demand-side systems — the trade-offs of letting software move prices and inventory in a hospitality setting are worked through in our piece on AI agents in hospitality revenue and dynamic pricing, and the boundary logic is the same: automate the reversible, escalate the consequential.
One note on our own portfolio, offered precisely rather than generously. Our published Pique Beverly Hills build is a Beverly Hills aesthetic clinic, not a restaurant — the case study describes a luxury website with a VIP concierge booking system, a private consultation request flow, encrypted messaging and after-hours VIP scheduling. We cite it here for one narrow reason: the booking-and-concierge pattern, including the discretion requirements around who may see what, is structurally close to a reservation-led restaurant's phone and booking stack. We are not claiming a restaurant outcome from it, and we would rather say that plainly than let an adjacent case study imply something it does not support.
What Breaks First
Restaurant agents rarely fail dramatically; they degrade quietly while a number on a dashboard stays green.The table below lists the failure modes we would instrument on day one, the signal that reveals each, and the rollback that contains it. Note that the detection signal is almost never “accuracy” — a single site-wide accuracy figure is the metric most likely to hide the problem.
| Failure mode | How you find out | Detection signal to instrument | Rollback |
|---|---|---|---|
| Menu drift — a price, modifier or 86'd item changes in the POS and not in the agent | Guests are quoted prices you no longer charge, or order items you cannot make | Nightly diff of the agent's menu snapshot against the POS export; alert on any delta older than one service period | Freeze the agent to read-only answers and route ordering to staff until the diff is clean |
| Accent, noise and lane-audio degradation | Repeat rates climb before accuracy does — Intouch measured repeats on 34% of AI orders against 22% overall | Track the repeat rate and the escalation-to-staff rate per lane per daypart, not a single site-wide accuracy number | Lower the confidence threshold so more orders escalate; a noisier lane should hand off sooner, not try harder |
| Silent human-in-the-loop dependency | Accuracy looks fine while staff are quietly fixing orders at the window all shift | Instrument staff-intervention events explicitly and report them next to the accuracy figure, never instead of it | Report both numbers to the operator every week; if intervention is doing the work, the business case is a staffing case |
| Consent configuration drift across states | A new site opens with the default configuration and no Illinois or California handling | Site-opening checklist item with a compliance owner; automated check that the state flag matches the deployed configuration | Disable voice capture at the affected site until the configuration is verified — inconvenience beats a class action |
| Vendor model change you did not schedule | Behaviour shifts overnight with no release note | Golden-set regression suite of recorded orders replayed weekly; contractual right to advance notice of model changes | Pin the previous behaviour if the contract allows it; otherwise escalate and increase staff coverage until the suite passes |
| Prompt injection through untrusted text | A review, a delivery note or a guest message contains instructions and the agent follows them | Log every tool call an agent makes and alert on any action initiated within a session that read external content | Revoke the write credential for that agent identity; injection is unsolved, so the control is blast radius, not detection |
| The integration you bought disappears in an acquisition | A partner logo quietly leaves the vendor's page and your connector deprecates | Watch every vendor's changelog and ownership status on a calendar; check acquisition news quarterly | Keep an exportable order and guest data path so switching costs stay bounded |
Two of those rows deserve elaboration. Silent human-in-the-loop dependency is the failure the SEC order documents at corporate scale and the Intouch data implies at lane scale. It is also the one that is easiest to detect and hardest to want to detect, because the fix is uncomfortable: if staff intervention is doing the work, the business case was a staffing case all along. Instrument intervention events explicitly, from day one, before anyone has a reason to prefer not knowing.
Prompt injection remains unsolved.Any agent that reads untrusted text — guest reviews, delivery-platform notes, supplier emails, inbound messages — can be instructed by that text, and no vendor filter reliably prevents it. Treat every detection percentage you are quoted with the same scepticism you now apply to accuracy figures. The workable controls are structural: keep the reading agent and the writing credential in separate sessions, scope credentials to the narrowest possible operation, log every tool call, and make sure the kill switch revokes the credential rather than pausing the code. That is blast-radius reduction, not prevention, and anyone selling you prevention is selling you something that does not exist yet.
The Human-in-the-Loop Boundary
Write the boundary down before you deploy, because it is much harder to argue for after an incident. The table below is the version we would put in front of a franchisee group: what an agent may do alone, what it may prepare for a human to commit, and what it must never touch regardless of how well it performs in testing.
| Action | Who may do it | Why the line sits here | Control that makes it safe |
|---|---|---|---|
| Answer hours, location, parking, and read a documented menu attribute back | Agent alone | Retrieval from a source you control, with no commitment and no health consequence | Single source of truth for menu data; log every answer with the record version it came from |
| Capture a standard order with no customisation | Agent alone, with a confirmation screen or read-back | This is the case the technology handles best and the one the third-party data still scores below human | Order read-back before payment; per-item confidence threshold that routes to staff |
| Capture an order with substitutions or modifiers | Agent proposes, staff confirms | Intouch found AI errors were most frequently attributed to order customization — the failure concentrates exactly here | Automatic escalation on any modifier; expediter screen shows what the agent heard, not just what it wrote |
| Answer “is this dish safe for my allergy?” | Never the agent | The liability is not delegable to a vendor whose contract disclaims it, and allergen substitutions are order customisations — the measured error category | Hard-coded escalation phrase list; staff trained to own the answer; no vendor configuration may override it |
| Book, move or cancel a reservation | Agent alone with reversibility | Reversible, low-consequence, and a confirmation message gives the guest a correction path | Confirmation text or email on every write; a nightly diff against the reservation system of record |
| Place a supplier purchase order | Agent proposes, a manager commits | This is the highest blast-radius autonomous action available in this roster — one vendor's ordering assistant sends POs | Value and variance thresholds; approval queue; idempotency so a retry cannot double-order |
| Build a schedule that assigns tipped and non-tipped duties | Agent drafts, a manager with wage-hour training approves | The restored dual-jobs regulation governs, and how a tool classifies duties is a legal question wearing a software costume | Duty classification is configuration a human owns and versions; keep the audit trail of who approved what |
| Run a pay run or apply tip automation | Never the agent unattended | Wage-hour errors are per-employee, per-pay-period, and compound quietly | Human sign-off with a variance report against the prior period; no straight-through processing |
| Make an employment decision — hire, discipline, terminate | Never the agent | Automated employment decision law is active and jurisdiction-specific | Screening support at most, with documented human decision authority and retained records |
| Publish a public response to a guest review | Agent drafts, a human sends | One bad automated reply outlives every good one, and prompt injection through review text is a live exposure | Draft state in your own system; treat review text as untrusted input; no send credential in a session that reads it |
The three “never” rows are not about capability. An agent could plausibly generate an allergen answer, run a pay run and draft a termination letter today. They are about where accountability has to sit when the answer is wrong: with a person who can be trained, supervised, and held responsible, working inside a process an auditor or a plaintiff's lawyer can reconstruct. Every one of those three has a real-world consequence that no vendor indemnity meaningfully covers.
The rows in the middle are where the actual value sits. An agent that captures a clean order, books a reservation, drafts a purchase order for a manager to approve and prepares a schedule for a wage-hour-trained human to sign off is doing substantial work with a defensible audit trail. That is a smaller claim than “autonomous restaurant operations,” and it is the claim that survives contact with a lane at Friday dinner.
Cost and Timeline
If a published-price product covers your workflow, buy it — we will tell you so on the call.A $399-per-location phone agent that answers your reservation line is not a build, and pretending otherwise would be bad advice. Custom work earns its keep when the workflow crosses systems you already own, when per-site configuration matters, or when the governance around consent and escalation has to be yours rather than a vendor's default.
| Engagement | Range | Timeline | What it covers in a restaurant context |
|---|---|---|---|
| Discovery + workflow audit | $9k–$22k | 2–4 weeks | Channel-by-channel volume baseline from your own call and POS data, a consent map by state, vendor contract review focused on the model-training clause, and a shortlist with the questions we would put in writing |
| Single-workflow agent | $28k–$70k | 4–9 weeks | One channel end to end — inbound phone, or reservations, or supplier ordering — with escalation paths, read-back confirmation, per-site configuration and an instrumented review queue |
| Multi-workflow platform with system integration | $70k–$180k | 9–16 weeks | Several workflows across POS, reservations and back-of-house, menu synchronisation with drift detection, a golden-set regression suite, consent configuration by state, and an operator reporting pack |
| Enterprise / multi-site / regulated build | $180k–$420k+ | 14–24 weeks | Multi-brand or multi-state rollout, per-site isolation, full audit logging with attribution, franchise-level access control, disaster recovery and restoration testing, and a documentation package a franchisor's counsel can review |
Senior-led work runs $150–$225 per hour. Ongoing retainers run $2,500–$9,500 per month, which for restaurant agents typically covers menu-drift monitoring, the regression suite, consent configuration as you open sites, and vendor change management. Every build carries a 30-day post-launch warranty, and full source-code and IP ownership transfers to you at delivery. We return a fixed-price phased proposal within 5 business days of a discovery call. Frenchy Digital is a senior-led, Black-owned agency based in Los Angeles; how we scope and stage this kind of work is described on our AI agent creation service page.
One sequencing note that saves money more often than any technical decision. Do the consent and contract work in the discovery phase, not after the pilot succeeds. Redlining a model-training clause during negotiation costs one email; discovering after rollout that your vendor has been training on eighteen months of guest audio across three states is a problem with no cheap ending.
Book a 60-Minute Restaurant AI Discovery Call
Bring your call-detail records and your POS export. You leave with a channel baseline from your own data, a consent map for your states, the two questions to put to every vendor in writing, and a fixed-price phased proposal within 5 business days.
Red Flags When Evaluating a Vendor
Each of these is something we observed while building this ranking, not a generic warning list. Treat any two of them appearing together as a reason to slow the process down.
- An accuracy or automation figure with no published definition. Ask what the denominator is and whether remote human agents count as automated. The SEC order turned on exactly that distinction.
- Refusal to state a human-in-the-loop rate in writing. No vendor in this roster publishes one voluntarily; the ones that will commit to a number contractually are telling you something the others are not.
- A model-training clause the vendor will not narrow. Under the CIPA capability theory this is the term that can convert a service provider into a third party. Silence on deletion schedules is the same red flag wearing a suit.
- Compliance badges with no reachable report. A badge is a graphic. A trust centre with named report types and dates is evidence. In this roster, one vendor cleared that bar.
- A product page that has not been updated in over a year while the sales pitch is about the newest capability. One vendor's AI page states its own last-updated date as December 2024.
- A flagship product you cannot find on the vendor's own site. If the URL 404s and the only references are secondary marketing coverage, do not put it in your evaluation matrix.
- A revenue calculator in place of a case study. Missed-call and phone-abandonment revenue estimates have no methodology, and we refuse all of them regardless of which vendor is publishing.
- Case-study figures with no method — a headline dollar amount attributed to a restaurant with no baseline, no period and no counterfactual.
- Stale corporate facts in the vendor's own materials: a competitor described as publicly traded when it was taken private, or an acquired product still marketed as independent.
- No published pricing combined with no published compliance and no named integrations. Any one of those is common. All three together means every claim in the sales cycle is unverifiable by construction.
- Reluctance to run a four-site pilot with your instrumentation rather than their dashboard. The measurement should be yours.
- A promise that prompt injection is handled. It is not handled anywhere by anyone. The right answer is a description of blast-radius controls.
Limitations and What We Could Not Verify
This section is part of the product, not a disclaimer at the end of it. Everything below is something we tried to check on 23 August 2026 and could not, or could only check through a secondary source. Naming it is the difference between a ranking and a sales page.
- No independent benchmark of these commercial products exists. The Intouch Insight study measures restaurant brands rather than vendors, never identifies which vendor powered which lane, and rests on 120 AI orders across three chains. It is the best third-party evidence available and it is not a product benchmark.
- No vendor in this roster discloses whether remote human agents complete or correct orders today. The only established instance is the SEC's finding about Presto Automation for the 2021–2023 period. This is the single most important undisclosed variable in the category.
- SOC 2, PCI DSS and ISO status could not be verified for most of the roster. Trust pages were absent, returned 404, or were gated. Only one vendor publishes full detail; two display badges without a reachable report.
- DPA availability, data residency and retention terms are not publicly disclosed by any vendor here. One publishes them behind an access-request gate. No vendor in this category publishes a DPA openly.
- Bikky could not be confirmed to be operating — both domains failed to resolve for us. We do not assert it shut down; we assert only that we could not confirm it trades, which is why it is not ranked.
- The Toast product referred to in secondary coverage as Sous Chef could not be confirmed on Toast's own site; the product URL returns 404. We therefore print neither the product as fact nor the average-order-volume figure attributed to it.
- The McDonald's 2026 drive-thru retry could not be confirmed from a credible source; the trade article we tried returned 403. We say only that McDonald's ended the previous IBM test, off in all restaurants by 26 July 2024, and is reported to be running a small new one. We do not print the order-volume or accuracy figures circulating about it.
- OpenTable's ownership was not verified this session, so we assert no parent company for it.
- Current FDA Food Code text could not be retrieved; every URL we tried returned 404. We state no edition year, adoption count or section number, and the allergen guidance here is reasoning, not regulation.
- Current federal tip-taxation provisions could not be verified this session, so no deduction amount, tax year, phase-out or occupation list appears anywhere in this article.
- Whether an AI agent changes tip-credit treatment under the restored dual-jobs regulation is unanswered by any source we located. Our framing is analysis and is labelled as such.
- The Seventh Circuit's April 2026 BIPA retroactivity decision is reported here from a secondary bar-association summary; we did not read the opinion.
- The Ambriz order itself was not fetched; we describe it through law-firm analyses and do not quote the court directly.
- The BIPA voiceprint class actions filed in May 2026 are described from the plaintiffs' own law firm's account. They are allegations, not findings.
- Turnover arithmetic is ours. BLS did not return an annual value, so we summed the twelve published monthly total separations rates for accommodation and food services — a series that includes hotels, because no restaurant-only series exists.
- Vendor customer lists, location counts and funding figures are as published by the vendor or reported in trade press, and we did not independently audit any of them.
Want an Honest Read on Your Restaurant AI Shortlist?
Book a free 60-minute discovery call. You leave with a channel-by-channel volume baseline from your own data, a consent map for the states you operate in, and a fixed-price phased proposal within 5 business days.
1517 S Bentley Ave Unit 204, Los Angeles CA 90025
Frequently Asked Questions
Sources & References
- 1SEC — In the Matter of Presto Automation Inc., Securities Act Release No. 11352, Admin. Proc. File No. 3-22413 (14 January 2025)↗
- 2Intouch Insight — 25th Annual Drive-Thru Study, released 1 October 2025 (methodology and findings)↗
- 3Restaurant Dive — coverage of the Intouch drive-thru AI findings (2 October 2025)↗
- 4QSR Magazine — the 2025 QSR Drive-Thru Report↗
- 5US Bureau of Labor Statistics — Current Employment Statistics, food services and drinking places (CES7072200001)↗
- 6US Bureau of Labor Statistics — JOLTS total separations rate, accommodation and food services (JTS720000000000000TSR)↗
- 7US Bureau of Labor Statistics — JOLTS quits rate, accommodation and food services (JTS720000000000000QUR)↗
- 8Parsa, Self, Njite and King — “Why Restaurants Fail,” Cornell Hotel and Restaurant Administration Quarterly 46(3):304–322 (2005), DOI 10.1177/0010880405275598↗
- 9Ohio State University — “Restaurant failure rate much lower than commonly assumed, study finds” (7 September 2003)↗
- 10740 ILCS 14/10 — BIPA definitions, including “voiceprint”↗
- 11740 ILCS 14/15 — BIPA retention schedule and written-release requirements↗
- 12740 ILCS 14/20 — BIPA damages and the single-recovery amendment↗
- 13National Law Review — the standing split in the McDonald's drive-thru voice AI litigation↗
- 14ABA Business Law Today — Seventh Circuit holds the BIPA damages amendment applies retroactively (Clay v. Union Pacific, No. 25-2185, 1 April 2026)↗
- 15California Penal Code § 631 — interception and the “aids, agrees with, employs, or conspires” clause↗
- 16California Penal Code § 632 — confidential communications and the reasonable-expectation exclusion↗
- 17Lexology — Ambriz v. Google, LLC, No. 3:23-cv-05437-RFL (N.D. Cal. 10 February 2025), the CIPA capability test↗
- 18FCC — Declaratory Ruling FCC 24-17, CG Docket No. 23-362 (adopted 2 February 2024, released 8 February 2024)↗
- 1947 U.S.C. § 227 — Telephone Consumer Protection Act (Cornell LII)↗
- 20Restaurant Law Center v. US Department of Labor, No. 23-50562 (5th Cir., opinion 23 August 2024)↗
- 21Federal Register — “Tip Regulations Under the FLSA; Restoration of Regulatory Language,” doc. 2024-29798, effective 17 December 2024↗
- 22US Department of Justice — ADA guidance on web accessibility (18 March 2022)↗
- 23SEC EDGAR — SoundHound AI, Inc. filing index (CIK 0001840856)↗
- 24SEC EDGAR — SoundHound AI Form 8-K/425 on the LivePerson merger, event date 20 July 2026↗
- 25Thoma Bravo — completion of the acquisition of Olo Inc. (12 September 2025)↗
- 26PR Newswire — ConverseNow acquires Valyant AI (10 July 2024)↗
- 27PR Newswire — ConverseNow and Deliverect partnership (16 April 2026)↗
- 28Nation's Restaurant News — Presto Automation sold to a Remus Capital-led investor group with $18 million of new capital (3 December 2024)↗
- 29Restaurant Dive — Presto Automation delisted from Nasdaq during its voice AI pivot↗
- 30CNBC — McDonald's to end its IBM AI drive-thru test (17 June 2024)↗
- 31Restaurant Dive — McDonald's and IBM end the automated order taking test↗
- 32Olo — trust centre (PCI DSS v4.0.1, SOC 1 Type 2, SOC 2 Type 2)↗
- 33Slang.ai — published pricing↗
- 34OpenTable — restaurant plans and published pricing↗
- 35ConverseNow — product site and named integration list↗
- 36SoundHound — restaurant product line↗
- 37Popmenu — AI phone answering product page↗
- 38Nory — agentic restaurant operating system and named assistants↗
- 39Restaurant365 — modules and R365 AI↗
- 40Toast — innovation hub (the destination for /toast-ai), stating its own last-updated date↗
- 41Hi Auto — AI Order Taker↗
- 42Presto — Presto Voice product site, © 2026 Presto Phoenix Inc.↗
- 43The D&O Diary — analysis of the SEC's AI-washing enforcement action against a restaurant technology company↗

