Contact center leaders are asking sensible questions about AI governance. They want to know where the risks sit, how regulation will affect operations and how to maintain trust with customers and agents.
The problem is that most AI risk is hidden inside the tools agents already use every day and it can be difficult to see where it is already at work. Many enterprises may already be using more AI than they realize.
AI is not simply present as a prominent chatbot or a formally approved GenAI project. In the contact center as a service (CCaaS) space, AI capabilities can be built into workforce management, agent assist, call summarization, sentiment analysis, quality monitoring, analytics, routing and software as a service (SaaS) platforms that enable new AI features by default.
This is where many leaders are caught off guard, Amit Namjoshi, Executive Director of Technology Consulting at TTEC Digital, told CX Today in an interview. “They don’t realize that it’s already there. All of this quality monitoring is done in the CCaaS space using some form of AI capability.”
That creates a governance challenge. If hidden AI is already operating in pockets of the business, customer experience leaders need visibility before they can classify the risk, assign ownership, document decisions or prove that the right human oversight is in place.
This is becoming a more pressing priority as organizations face a growing set of expectations around the responsible use of AI. The EU AI Act introduces risk-based requirements for certain AI systems and while the EU GDPR applies wherever AI processes personal data. Frameworks such as ISO/IEC 42001 and the NIST AI Risk Management Framework also give organizations structured approaches for managing AI risks across the technology lifecycle. All this means that knowing where AI exists in an enterprise is becoming a prerequisite for knowing whether it is being used appropriately.
As Namjoshi explained:
“When we do an inventory for organizations and we tell them that these are the places where they’re actually using AI, very often that is a surprise because they think they are just starting on it or embarking on it because they have got a PoC and they've actually not enabled Copilot Studio.”
Leaders may assume their teams are not already using AI, “but that's not the case,” Namjoshi added.
Here are five steps for leaders to follow to identify where hidden AI may be used in their organization and bring it under clear oversight.
Step One: Discover Where AI Is Being Used
The first step in any contact center AI audit is visibility.
Before leaders can decide whether the AI used in the business is compliant, appropriate or well-governed, they need to know where it exists. That means looking beyond obvious AI deployments and examining the tools already used across service operations.
This is where TTEC Digital starts, Namjoshi said.
“The first thing we ask is, do you have an AI inventory? And can you share that with us? Often the answer is no.”
An inventory should cover customer-facing and employee-facing systems, including CCaaS tools, CRM workflows, agent desktop applications, QA tools, workforce management, analytics platforms, knowledge systems and any AI-assisted productivity tools used by agents, supervisors or support teams.
The reason is simple.
“If you don't see the problem, you are never going to solve the problem. So seeing it is the first step,” Namjoshi pointed out.
Step Two: Classify the Risk and Customer Impact
Once AI is visible, leaders need to understand what each use case actually does.
Not all AI carries the same level of risk. A tool that helps draft an internal summary is different from one that recommends a customer response, prioritizes an escalation, analyzes sentiment or influences a service decision.
Customer-facing AI is where caution becomes especially important, Namjoshi noted.
“This is particularly damaging if it is customer-facing, because anything that is going out to the customer and you aren't really sure that the information is authentic can spell trouble.”
A practical audit should classify AI by impact. Does it touch customer data? Does it generate information sent to a customer? Does it influence a decision? Does it affect workforce allocation? Does it change how an agent handles a case?
A simple three-tier model could help CX leaders prioritize AI governance:
-
Low risk: AI used for internal productivity, such as summarization, transcription or knowledge retrieval, where outputs are reviewed by employees before use.
-
Medium risk: AI that recommends actions, prioritizes work, analyzes customer sentiment or influences how an agent handles an interaction.
-
High risk: AI that communicates with customers directly, makes or influences decisions about customers or employees, accesses sensitive personal data, or takes autonomous actions in a customer-facing workflow.
The classification should then determine the level of testing, human oversight, documentation and ongoing monitoring required.
Step Three: Document Data, Decisions, and Ownership
The next step is documentation. For every AI use case, organizations should capture what the tool does, what data it uses, who owns it, what outputs it produces and where it sits in the service process.
These are the kinds of questions that build confidence, Namjoshi said.


