85% of contact centre operations now blend human agents with AI agents on live customer conversations. That figure was a pilot statistic eighteen months ago. It is now the default operating model, and it happened faster than most organisations built the governance to match it.
We are starting to see vendors respond to the gap directly, launching governance and talent layers purpose-built for agentic contact centre platforms rather than bolting generic enterprise AI governance onto a CX stack. That's a useful signal. It means the market has noticed what we've been telling clients for a year: contact centre governance is not a smaller version of enterprise AI governance. It is a different problem.
Why the generic model doesn't fit
Enterprise AI governance is built for decisions that happen on a cadence - quarterly model reviews, committee sign-off, documented risk assessments before a model goes live. A contact centre agent doesn't work on a cadence. It makes a tone decision, a disclosure decision, and sometimes a commitment decision inside a single call, in real time, with no committee in the loop.
That mismatch is where the risk actually sits. Not in the model's accuracy - most of these systems are accurate. In what happens in the two seconds after the model produces an output that nobody reviews before the customer hears it.
What's specific to the contact centre
- Disclosure. Does the customer know they are talking to an AI agent, and does that disclosure meet the regulatory bar in every market you operate in - not just the one where you built the policy
- The right to a human. A defined, low-friction escalation trigger, not a hidden menu option three layers deep
- Commitment authority. What can the agent promise - a refund, a rate, a resolution timeline - and what happens when it promises something outside policy
- Call-level audit trail. Not aggregate accuracy dashboards. The ability to reconstruct exactly what was said, decided, and disclosed on any single call, on demand
- Tone and compliance drift. Monitoring that catches a model quietly getting more aggressive on collections calls or looser on eligibility questions, not just monitoring that catches technical failure
This is a different governance discipline from the one covered by most enterprise agent governance frameworks, which we've written about separately. That work is necessary. It is not sufficient for a channel where the agent is talking directly to your customer.
What good looks like
The operations that have got this right run four things as standard, not as an afterthought bolted on after a near-miss:
- A written disclosure and escalation policy reviewed by legal and compliance, not just product
- Full-transcript recording and retrieval for every AI-handled interaction, retained on the same schedule as human-agent calls
- A defined commitment ceiling - a hard limit on what the agent can offer without human sign-off, enforced in the system, not in a training document nobody reads
- Weekly, not quarterly, quality sampling specifically for tone and compliance drift, run by someone who isn't the team that built the model
None of this is difficult. It is mostly unbuilt, because organisations moved the agents into production faster than they moved the governance function to keep pace.
A real pattern
We reviewed a retail bank's AI-handled collections calls after a customer complaint escalated to the regulator. The agent had not said anything technically false. It had, however, used language that drifted noticeably more assertive than the approved script over a six-week period, with nobody monitoring for that specific pattern because the accuracy dashboard looked fine throughout. The fix took two weeks. Finding the problem took a formal complaint.
The bottom line
Blended human-AI contact centres are no longer the exception you're piloting. They're the operating model you're running. The governance layer for that model has to be built for what actually happens on a live call - not adapted from a framework designed for quarterly model reviews. Build it before the regulator, or the customer complaint, builds it for you.