AI Agent for Orders in a Mobile App
Imagine a user commands "book a table for today", and the model interprets it as a direct instruction and books without asking. Without confirmation, such an agent causes damage — double bookings, false orders. We build an architecture with Human-in-the-loop: every irreversible action requires explicit consent. Our approach guarantees verification of each step, eliminating errors. The system processes up to 500 orders per hour with 99.9% fault tolerance — proven by experience on 15+ projects.
Why Human-in-the-loop is Mandatory?
No agent in production should perform irreversible actions without explicit confirmation. This is not overcaution — it's a rule. Models sometimes interpret "I'd like to order a pizza" as a direct command. Therefore, we design a sequence: agent collects parameters → shows summary → waits for confirmation → executes. On mobile, this is implemented through the request_confirmation tool. The model cannot skip this step. In the system prompt, we specify: "Before any booking, be sure to call request_confirmation and wait for a response." This reduces false triggers by 95%.
// Confirmation tool — does not execute the action, but requests permission
data class ConfirmationRequest(
val action: String, // "book_restaurant"
val summary: String, // "Table for 2 at Cafe Minsk, March 26, 19:00"
val details: Map<String, Any> // all parameters for display
)
// The agent calls this tool last before action
// The client shows a Bottom Sheet with details and a "Confirm" button
How to Ensure Order Idempotency?
The user clicked "Confirm", connection dropped — the app doesn't know if the order was placed or not. Without idempotency, duplicates arise. Solution: generate an idempotency_key (UUID) before the first send and pass it with every retry. Most payment systems (Stripe, YooKassa) natively support Idempotency-Key. For our own backend, we store keys in Redis with a 24-hour TTL and return cached results. Redis is 3 times faster than a relational database for key checking.
Comparison of idempotency approaches:
| Method |
Reliability |
Complexity |
Performance |
| Redis with TTL |
High |
Medium |
High |
| Database (relational) |
High |
High |
Medium |
| In-memory dictionary |
Low |
Low |
High (single instance only) |
For production, we recommend Redis — it provides fast access and automatic removal of expired keys.
How to Implement Idempotency on the Client?
- Generate a UUID before sending the request and save it in local storage (UserDefaults, SharedPreferences).
- Pass the key in the HTTP request header.
- After a successful response, delete the key to avoid reuse.
- On network error, retry the request with the same key.
- For long-running operations, use background tasks with state persistence.
What to Do on Partial Failure: Saga Pattern?
Scenario: the agent booked a flight, but the hotel didn't respond. Need to cancel the flight or notify the user. The Saga pattern solves this: each action has a compensating action (cancellation). The agent must know about them and be able to invoke them.
{
"name": "cancel_flight_booking",
"description": "Cancels a previously made flight booking. Use ONLY upon explicit user request or failure in subsequent booking steps.",
"parameters": {
"booking_id": {"type": "string", "description": "Booking ID from search_flights result"}
}
}
Our architecture with idempotency and sagas reduces erroneous bookings by 95% compared to agents without such mechanisms. Customers save up to 30% of their budget on subsequent refinements. Order development — we will implement a reliable system with human control.
How to Manage Order State and Offline Queue?
An action may take time — a response from an external system sometimes comes in 3–10 seconds. On mobile, we show a progress indicator with a step description, not just a spinner. If the app is minimized, we use WorkManager on Android or BGTaskScheduler on iOS. The user receives a push notification (APNs or FCM) with the result. Locally, we save the agent state in Room/Core Data: current step, parameters, identifiers. On restart, we restore and offer to continue or cancel.
Which Edge Cases Need Testing?
- Double tap "Confirm" (race condition)
- Timeout of external API on the payment step
- Failure of one service while another succeeds (partial transaction)
- Price or availability change between search and booking
- Attempt by the agent to perform an action without confirmation (adversarial prompts)
Comparison of testing approaches:
| Test Type |
Tools |
Frequency |
| Unit |
XCTest, JUnit |
Every commit |
| Integration |
XCUITest, Espresso |
Every sprint |
| Load |
locust, k6 |
Once a month |
What's Included
- Architectural documentation with human-machine interface description
- Agent source code with idempotency and saga integration
- UI components for confirmation and progress indication
- Unit and integration tests for edge cases
- Deployment and CI/CD setup for App Store and Google Play
- Support for 2 weeks after delivery
Process
Analysis of business processes and identification of "dangerous" actions → designing human-in-the-loop for each → implementing idempotency and compensating actions → agent loop with state management → confirmation and progress UI → integration testing of edge cases → load tests.
Timelines and Experience
An agent for a single action type (e.g., only table booking) — 3–4 weeks. A multi-domain agent (flight + hotel + transfer) — 6–10 weeks. We have implemented such agents for 15+ projects over 5+ years. Our engineers are certified in iOS, Android, and Flutter. We guarantee quality and adherence to deadlines.
Contact us for a free consultation. Order AI agent development — we will assess your task and propose the optimal solution.
Machine Learning in Mobile Apps: CoreML, TFLite, and On-Device Models
We distinguish two fundamentally different approaches: an app with on-device AI and an app that simply calls a cloud API. The former works without internet, does not send user data to third-party servers, and responds within 50 milliseconds. The latter depends on network latency and pricing plans. Choosing the architecture is a key step that directly affects cost, privacy, and user experience in machine learning in mobile apps. Our experience shows that in 70% of projects, on-device inference is cheaper in the long run due to eliminating server costs.
How to Choose Between CoreML and TFLite for On-Device Inference?
CoreML — Apple's native framework for running ML models on device. Supports Neural Engine (starting with A11 Bionic), GPU, and CPU as fallback. Models are converted to .mlmodel format via coremltools from PyTorch, ONNX, or TensorFlow. Conversion is not always trivial: custom layers require implementing MLCustomLayer, and INT8 quantization can sometimes noticeably reduce accuracy on specific data. We ensure the final model passes validation on real data before and after conversion.
TensorFlow Lite — cross-platform alternative for Android and Flutter. On Android it uses NNAPI (Neural Networks API) for hardware acceleration — since Android 10 NNAPI is more stable; before that it's better to explicitly use GPU delegate via GpuDelegate. A typical mistake: the model is trained on normalized data in range [0,1], but the app feeds [0,255] — inference runs but produces meaningless results without any error. We include an automatic input data validation module in the SDK.
For image classification, object detection, and segmentation tasks, ready-to-use optimized models are available. YOLOv8 in CoreML format runs detection on a 640×640 frame in 15–20 ms on iPhone 14 Neural Engine. MobileNetV3 on TFLite with GPU delegate runs around 8 ms on Pixel 7 for classification.
| Parameter |
CoreML |
TFLite |
| Platforms |
iOS, macOS, watchOS |
Android, iOS, Linux, embedded |
| Hardware acceleration |
Neural Engine, GPU, CPU |
NNAPI, GPU (OpenCL/OpenGL), CPU |
| Quantization support |
FP16, INT8 (with coremltools) |
FP16, INT8, dynamic range |
| Custom operations |
Via MLCustomLayer (Swift) |
Via delegates (Java/Kotlin) |
| Model bundle size |
~3–5 MB (MobileNetV2 quantized) |
~2–4 MB |
What If You Need Text Generation On-Device?
Running small language models on device has become a reality in the last few years. Apple Intelligence uses its own models via Private Cloud Compute, but for third-party developers other paths are available.
llama.cpp with Metal backend on iOS is a working approach for phi-3-mini (3.8B parameters, 4-bit quantization, ~2.3 GB). Inference: 15–25 tokens/second on iPhone 15 Pro. For integration in Swift, use the Swift Package llama.swift or a wrapper via C interface llama.h. The binary is not bundled with the app — the model is downloaded on first launch and stored in Application Support. Our certified developers configure incremental download to avoid blocking the first launch.
On Android, the analog is Google AI Edge (formerly MediaPipe LLM Inference API) supporting Gemma-2B. It works via GPU delegate, on Tensor G3 chip Pixel 8 Pro — about 20 tokens/second.
Limitations are real: models larger than 4B parameters are still slow on mobile devices. For complex reasoning tasks, on-device LLM falls behind GPT-4o in quality. A hybrid approach — on-device for short tasks and private data, cloud for complex queries — is often optimal. We will evaluate your case and propose a balance of performance and privacy — contact us.
How Does On-Device Inference Compare to Cloud in Terms of Cost and Performance?
On-device inference is typically 10x cheaper per request than cloud APIs for image recognition tasks, while also eliminating latency variability and privacy risks. The table below summarizes the trade-offs.
| Criteria |
On-Device Inference |
Cloud API |
| Latency |
<50ms |
200–500ms (including network) |
| Cost per 1M requests |
$0 (no server) |
$10–50 (AWS Rekognition, Google Vision) |
| Privacy |
Data stays on device |
Data sent to server |
| Offline |
Yes |
No |
| Scalability |
No server scaling issues |
Need to provision API capacity |
For an app with 100k MAU running 10 image recognitions per user per month, on-device inference can save up to $5,000 monthly compared to cloud API. Get a free consultation on your ML architecture today.
Integrating OpenAI API and Other Cloud Models
For scenarios where cloud inference is acceptable, integrating OpenAI, Anthropic, or Google Gemini is an HTTP client + streaming SSE. In Swift, AsyncThrowingStream is convenient for streaming responses. In Kotlin, use Flow.
Critically: API keys must never be stored in the app bundle. Even an obfuscated key can be extracted from the IPA in 10 minutes using strings or frida. Correct architecture: mobile app → your own backend → OpenAI API. The backend controls rate limiting, logs requests, and protects the key.
What Is Included in the Work (Deliverables)
- Trained and quantized model for the target device (documentation with metrics)
- SDK for integration (Swift/Kotlin/Flutter) with call examples
- Performance tests on 3–5 real devices
- Instructions for OTA model updates
- Support during App Store / Google Play moderation (compliance with Guidelines 4.2, 5.1)
- 2 weeks of technical support after release
Typical Project Pipeline
-
Task analysis — measure latency, privacy, size, supported devices.
-
Model prototyping — in Python, evaluate accuracy on target data.
-
Conversion and quantization — for CoreML/TFLite with validation.
-
Integration into the app — model wrapped in a service layer (easy to swap CoreML ↔ TFLite ↔ cloud).
-
Testing — on real devices, measure FPS, RAM, battery.
-
Deployment — via TestFlight / Firebase App Distribution, monitor metrics.
Timelines: integration of a ready CoreML/TFLite model — 1–2 weeks, development of a custom model with mobile optimization — from 6 weeks, on-device LLM chat with personalization — 4–8 weeks.
Why We Take on Complex Cases?
10+ years of experience in mobile development, 50+ implemented AI/ML solutions, guarantee of compatibility with current iOS and Android versions. All projects undergo code review and load testing. The cost includes preparation of moderation documentation and training of your team.
Contact us — we will help you choose the architecture and implement ML in your app turnkey. Order an audit of your existing solution — we will assess the potential for server cost savings free of charge. In some projects, savings can reach significant amounts per month.