The contact centre market across the Asia-Pacific (APAC) region is entering a new operational phase. Rapid advances in artificial intelligence (AI), coupled with the expansion of hyperscalers and modern customer experience (CX) platforms, are accelerating a transition away from traditional telephony-first and interactive voice response (IVR) operating models.
In their place, organisations are deploying AI-enabled platforms capable of managing increasingly complex customer interactions.
Audrey William, Founder and Principal Analyst at CrayonIQ and Andrew Milroy, Chief Analyst for AI governance and cybersecurity research firm Veqtor8, co-authored a report recently, Risk, Governance and Data Sovereignty are at the centre of every AI Deployment in the Contact Centre, that explores the underlying issues and trends.

William comments, “This technology shift coincides with heightened regulatory scrutiny. Highly regulated industries across the region are enforcing stricter requirements around AI governance, privacy, and data sovereignty. As a result, enterprise technology buyers face the challenge of adopting advanced AI capabilities while adhering to complex compliance, governance, and accountability standards”.
For procurement and technology teams, AI has broadened the standard evaluation criteria. Decision-making frameworks now extend beyond core functionality, customer experience, and total cost of ownership (TCO) to evaluate AI governance, data sovereignty, commercial models, and long-term operational resilience.
Data sovereignty in enterprise procurement
Generative AI applications rely heavily on large volumes of customer interaction data, including contact centre transcripts, voice recordings, and multi-channel customer conversations. While these inputs are necessary for training and operating AI-enabled CX solutions, they also carry regulatory implications.
Milroy comments, “Governments across APAC are strengthening expectations around data privacy, AI governance, and national control over sensitive information. Regulatory bodies in multiple jurisdictions are extending existing frameworks governing financial services, privacy, and critical infrastructure to encompass AI deployments specifically”.
Consequently, enterprise procurement teams are required to examine where customer data is hosted, how it is processed, and which legal jurisdictions govern technology suppliers. “Understanding cross-border data flows and vendor jurisdiction has become a standard requirement, particularly within financial services, healthcare, telecommunications, and the public sector”, says Milroy.
Differentiating data residency from sovereignty
A critical distinction in modern procurement programs is the difference between data residency and data sovereignty.
- Data residency: Refers specifically to the physical geographical location where data is stored at rest.
- Data Sovereignty: Extends to the legal jurisdiction, operational control, and long-term legal independence surrounding that data.
Storing customer interactions within a local data centre does not automatically guarantee full sovereignty if the underlying cloud provider is headquartered or incorporated in a foreign jurisdiction subject to extraterritorial legal requests.
A comprehensive assessment of sovereignty encompasses six core areas:
- Data Sovereignty: Evaluating the sensitivity of customer information against applicable regional regulatory obligations.
- Jurisdictional Sovereignty: Assessing the legal frameworks and extraterritorial laws that govern each supplier.
- Operational Sovereignty: Managing operational dependency on specific cloud, AI, or platform vendors.
- Model Sovereignty: Maintaining organizational ownership over prompts, model weights, custom configurations, and institutional knowledge.
- Political Sovereignty: Mitigating exposure to international geopolitical shifts or foreign government interventions.
- Technical Sovereignty: Ensuring the technical capacity to audit, modify, or migrate platform components without excessive vendor lock-in.
While traditional procurement processes often focus primarily on physical data residency, AI integration necessitates evaluating these broader legal and operational dimensions.
Managing Voice AI and operational risk
Voice AI introduces unique governance considerations due to the rich nature of unstructured audio data. William comments, “Unlike plain text, audio recordings contain biometric, tonal, and identity markers that fall under stringent privacy protections. Concurrently, the rise of synthetic voice generation and deepfake technologies has heightened security risks related to unauthorized access and fraud”.
Organisations operating at scale, such as financial institutions, airlines, telecommunications providers, and government agencies, face rising requirements for identity verification, auditability, and human oversight. Milroy warns, “Because enterprise contact centres process high interaction volumes, minor failures in automated governance can rapidly compound across thousands of customer engagements, leading to operational, legal, and reputational risk”.
Addressing these risks requires governance structures that look beyond standard model accuracy to enforce explicit consent mechanisms, secure identity management, and continuous audit logging.
Executive accountability and CX strategy
The ownership of customer experience strategy has expanded beyond traditional contact centre operations. William highlights, “Decisions regarding enterprise AI deployment now involve executive leadership teams, including the Chief Executive Officer, Chief Information Officer, Chief Digital Officer, Chief Risk Officer, and emerging Chief AI Officer roles”.

“This cross-functional executive involvement reflects the strategic impact of AI on workforce design, operational risk, and service differentiation. Defining where automated systems operate autonomously, and where human intervention remains mandatory, is both a compliance requirement and a core business driver”, adds Milroy.
Evolving commercial models and outcome economics
Commercial structures for contact centre technology are shifting alongside the underlying architecture. “Traditional platforms historically relied on seat licensing, agent tiers, or fixed interaction volumes. AI-driven platforms, however, introduce compute-based pricing models driven by token usage across inference, context retrieval, and reasoning engines”, notes William.
“In response, technology vendors are increasingly introducing outcome-based commercial models designed to link pricing to specific business results rather than raw resource consumption”.
Evaluating these modern commercial structures requires analysing the total cost ecosystem. Delivering a successful customer outcome involves the combined performance of underlying AI models, orchestration layers, enterprise integrations, knowledge bases, human advisers, and compliance frameworks.
According to William, organisations evaluating modern commercial models require full visibility into:
- The underlying cost drivers across computational and human inputs.
- The operational ratio of automated versus human-driven tasks.
- The specific governance controls applied to autonomous workflows.
- Transparent metrics for measuring tangible business value and customer satisfaction.
Governing critical handoff points in the customer journey
As AI becomes integrated into complex customer journeys, managing the transition points where operational responsibility shifts becomes a critical operational requirement. William advises, “Failures at these handoff points can lead to context loss, inconsistent decision-making, elevated operating costs, and reduced customer trust”.
AI-to-AI handoffs
Modern interactions frequently rely on multiple specialised AI components, such as intent routers, retrieval-augmented generation (RAG) systems, workflow automation, and specialized domain models, working in sequence. William comments, ““When managing AI-to-AI handoffs across complex model chains, maintaining operational integrity is critical. Modern customer interactions increasingly rely on multiple specialised AI components, ranging from intent routers and retrieval-augmented generation systems to workflow automation and domain-specific models, working in sequence”.
Maintaining operational integrity across these chains requires accurate context retention, explicit functional boundaries for each model, and step-by-step auditability. Organizations must be equipped to reconstruct the entire sequence of automated decisions that led to a final resolution.
Structured knowledge transfer
When an interaction escalates from an automated system to a human agent, continuity is essential. Rather than simply transferring a call or chat session, platforms must execute a structured knowledge transfer.
William says, “Human advisers require a consolidated summary containing the customer’s intent, prior actions taken, verified account details, and the explicit reason for escalation. Furthermore, escalation rules must prioritize regulatory, vulnerability, or high-risk scenarios (such as financial hardship or healthcare inquiries) for early human intervention:.
Mitigating hallucinations and errors
The final handoff occurs when an AI system directly communicates output to a customer. At this stage, governance becomes directly visible to the market.
Ensuring output accuracy relies heavily on real-time knowledge management. Automated responses must be grounded strictly in verified corporate policies, approved knowledge repositories, and compliance guidelines. Establishing precise confidence thresholds determines whether an AI system can respond autonomously or must route the interaction to a human team member to maintain data accuracy and brand trust.