Safely manage your Zendesk from the AI assistant you already use, via the Deltastring MCP. Beacon configuration platform
← Back to news

AI Security: What Contact Center Leaders Need to Get Right

Contact center leaders deploying AI are confronting a fundamental tension: the technology promises operational efficiency and improved customer experience, yet introduces material security risks that demand governance frameworks equivalent to those governing human agent access. The UC Today discussion with New Era Technology's Matt Kamish establishes that AI security in contact centers extends far beyond perimeter defence. The core challenge centres on data minimization and access control—ensuring AI systems access only the specific customer data required for individual transactions rather than broad database permissions. This requires implementing least-privilege access protocols, redaction of personally identifiable information, encryption both in transit and at rest, and segmentation of AI systems to contain breach impact. Critically, these controls must be enforced at the vendor level through rigorous assessment of third-party platforms and contractual guardrails around data handling, storage, and model behaviour. For teams already operating Zendesk, Salesforce Service Cloud, or similar platforms, this raises an immediate operational question: how thoroughly are you auditing the AI integrations and third-party connectors you've already deployed, and do your vendor contracts explicitly address AI-specific data governance?

The discussion reveals that deployment represents only the beginning of the security lifecycle. Continuous monitoring emerges as non-negotiable—real-time behaviour tracking, anomaly detection, transaction logging, and regular testing for model drift and bias. Organizations must establish dedicated AI governance structures with clear ownership, transparent oversight mechanisms, and documented policies around prompt injection defences, API call restrictions, and data retention. The emphasis on continuous monitoring reflects a sobering reality: chatbots offering unauthorized discounts or inadvertently exposing customer information from previous interactions are not edge cases but predictable failure modes when governance lapses. This operational burden raises a practical concern for support team leads and CX consultants: do your current monitoring and logging capabilities—whether native to your platform or bolted on through third-party tools—actually provide the auditability and real-time visibility required, or are you operating with visibility gaps that could mask model drift or malicious manipulation until damage occurs?

Governance and accountability frameworks must also address customer transparency and regulatory compliance. The EU AI Act and standards such as SOC 2, ISO 27001, GDPR, and HIPAA are no longer optional considerations but mandatory baselines. Organizations must communicate AI involvement to customers explicitly, establish clear accountability for AI decisions, and maintain audit trails sufficient to demonstrate compliance. This represents a cultural shift from treating AI as a deployment tool to treating it as a supervised system requiring the same rigorous oversight applied to human agents—with the added complexity that AI systems can scale failures across thousands of interactions simultaneously.