Skip to main content

Business Briefing

Enterprise Customer-Service AI: Complete Business and Product Blueprint

I will use a fictional company so the use case is concrete.

Business scenario

Company: NovaConnect Industry: Telecommunications Markets: UK, EU and selected Asia-Pacific (McKinsey & Company)on Channels: Voice, web chat, mobile app, email, WhatsApp and social media Current annual customer-service cost: Approximately £21 million Proposed product: NovaAssist — a security-first AI customer resolution platform

Because no actual organisational baseline has been supplied, the “current position” below represents a typical enterprise starting point rather than an assessment of a specific company.

1. Executive proposition

The business problem

NovaConnect currently has:

  • High volumes of repetitive billing, account, network and device enquiries

  • Different answers being provided across channels

  • Long waiting times during outages and billing periods

  • Agents switching between CRM, billing, order management and network systems

  • Limited 24/7 support

  • High costs from contact-centre growth

  • Weak visibility into why customers contact the company

  • Customers repeating information during escalation

  • Poor conversion from service conversations into retention or sales opportunities

Proposed solution

NovaAssist would combine:

  • AI customer self-service

  • Human-agent assistance

  • Deterministic business workflows

  • Secure integration with enterprise systems

  • Multilingual support

  • Human escalation

  • Customer journey analytics

  • Continuous AI evaluation

  • Governance, security and compliance controls

The proposition is:

Resolve routine customer needs immediately, guide complex enquiries safely and give human agents full context when judgement or empathy is required.

Strategic objective

The company is not merely implementing a chatbot. It is creating an AI-enabled customer operations platform that can support service, sales, retention, marketing and operational intelligence.

2. Detailed end-to-end use case

Use case: Unexpectedly high mobile bill

Step 1: Customer enters the journey

The customer opens the mobile application and writes:

“Why is my bill £40 higher this month?”

The interface clearly states:

“You are speaking with NovaAssist, our AI service assistant. You can ask to speak with a person at any time.”

This disclosure is important for customer trust and is increasingly relevant to regulatory transparency requirements. EU AI Act transparency obligations requiring users to be informed when they interact with an AI system are due to apply from 2 August 2026. (Digital Strategy EU)ty and authentication

The system determines that account-specific data is required.

The customer authenticates using:

  • Existing mobile-app session

  • MFA for higher-risk actions

  • Step-up authentication for payment, SIM or account-owner changes

  • Device and session-risk signals

The AI itself does not decide whether authentication is sufficient. A deterministic identity service makes that decision.

Step 3: Intent classification

The AI identifies:

  • Primary intent: bill explanation

  • Secondary concern: possible overcharging

  • Sentiment: concerned

  • Risk classification: medium

  • Relevant systems: billing, tariffs, usage and previous interactions

The AI must not directly retrieve arbitrary customer records. It requests access through an authorised tool gateway.

Step 4: Deterministic data retrieval

A controlled billing API returns:

  • Current bill: £82

  • Normal monthly bill: £42

  • Additional cost: £40

  • Cause: international roaming

  • Usage dates and country

  • Applicable tariff

  • Whether the charge meets the contract rules

  • Whether the customer received a roaming notification

The billing system—not the language model—calculates the charge.

Step 5: AI explanation

NovaAssist translates the structured billing data into clear language:

“Your bill is £40 higher because your phone used mobile data in Switzerland between 4 and 6 July. Switzerland is outside your current inclusive roaming zone. You used 1.8 GB, resulting in £40 of roaming charges.”

The response includes:

  • A source link to the relevant tariff

  • A breakdown of the charge

  • The date and type of usage

  • An explanation of future prevention options

Step 6: Resolution options

NovaAssist offers approved actions:

  • View detailed usage

  • Add a roaming package

  • Set a roaming spending limit

  • Raise a billing dispute

  • Speak to a person

The AI cannot invent a discount. Eligibility is checked by a deterministic policy engine.

Step 7: Retention and sales opportunity

The policy engine determines that:

  • The customer travels internationally regularly

  • A £12 monthly roaming add-on would have reduced the latest charge

  • The customer is eligible

  • Marketing consent permits an offer

NovaAssist says:

“You may benefit from our Global Roaming Add-on at £12 per month. Based on your recent usage, it could reduce similar charges in the future.”

This turns customer service into a relevant sales opportunity without using the interaction for unrestricted selling.

Step 8: Complaint or human escalation

The customer writes:

“I was never warned. I want this refunded.”

The system identifies a possible complaint.

NovaAssist:

  • Stops promotional messaging

  • Creates a complaint case

  • Summarises the conversation

  • Attaches the billing evidence

  • Records the notification status

  • Transfers the customer to an authorised agent

  • Provides an estimated waiting time

The customer does not need to repeat the issue.

Step 9: Agent support

The human agent receives:

  • Verified customer identity

  • Issue summary

  • Billing evidence

  • Relevant contract clause

  • Previous contacts

  • Recommended next action

  • Refund authority limit

  • Customer sentiment

  • Compliance warnings

The agent can accept, modify or reject the AI recommendation.

Step 10: Transaction

Where a refund is approved:

  • The agent or authorised workflow initiates it

  • A deterministic finance service validates the amount

  • Segregation-of-duties rules are checked

  • The action is recorded in an immutable audit log

  • The customer receives confirmation

Step 11: Feedback

After resolution:

“Was your issue resolved?”

The system records:

  • Resolution outcome

  • Customer satisfaction

  • Whether escalation was needed

  • Whether the recommendation was accepted

  • Refund outcome

  • Repeat contact within seven days

  • Conversation quality

Step 12: Organisational learning

Aggregated analytics may identify that:

  • Roaming complaints increased 28%

  • Customers are not seeing warnings

  • Switzerland-related enquiries have increased

  • A particular mobile-app journey is confusing

  • A tariff page contains ambiguous wording

That insight is sent to:

  • Customer operations

  • Product management

  • Network operations

  • Marketing

  • Legal and compliance

  • Digital experience teams

This is the difference between a chatbot and an enterprise customer-intelligence platform.

3. Customer lifecycle coverage

Customer stageAI capabilityBusiness outcome
AwarenessProduct questions, coverage checks and comparisonsIncreased qualified traffic
ConsiderationPlan recommendation and eligibility screeningHigher conversion
PurchaseGuided checkout and document collectionLower abandonment
OnboardingSIM activation, account setup and tutorialsFaster activation
UsageTechnical support and network-status guidanceLower service demand
BillingBill explanations, payments and disputesReduced billing contacts
Service recoveryOutage support and proactive notificationsLower frustration
RetentionChurn-risk identification and approved offersImproved retention
ExpansionRelevant upgrades and add-onsIncreased customer value
ComplaintComplaint recognition and regulated workflowBetter compliance
CancellationCancellation support and reason captureRetention insight
Post-exitFinal billing and feedbackReduced repeat contact

4. Product capability model

Customer-facing capabilities

  • Natural-language chat and voice

  • Multilingual service

  • Identity-aware personalised responses

  • Account and order enquiries

  • Billing explanations

  • Product recommendations

  • Transactional actions

  • Complaint recognition

  • Human escalation

  • Accessibility support

  • Proactive notifications

Agent-facing capabilities

  • Real-time answer recommendations

  • Knowledge retrieval

  • Case and conversation summaries

  • Sentiment and vulnerability indicators

  • Next-best action

  • Compliance reminders

  • Form completion

  • Automatic CRM updates

  • Quality-assurance support

  • Coaching recommendations

Supervisor capabilities

  • Live-risk monitoring

  • Resolution analytics

  • AI and human quality scoring

  • Knowledge gaps

  • Escalation patterns

  • Cost and utilisation reporting

  • Agent-adoption monitoring

  • Customer-journey failure analysis

  • Model and prompt performance

  • Incident management

5. Deterministic AI operating model

A customer-service platform should not use generative AI for every task.

The preferred design is:

Probabilistic language experience over a deterministic transaction core.

Generative AI should handle

  • Intent recognition

  • Language understanding

  • Summarisation

  • Translation

  • Tone adaptation

  • Knowledge retrieval

  • Explanation

  • Drafting

  • Conversation management

Deterministic systems should handle

  • Identity verification

  • Account entitlement

  • Prices and billing calculations

  • Refund limits

  • Credit decisions

  • Contract eligibility

  • Regulatory disclosures

  • Payment execution

  • Data-retention rules

  • Authentication requirements

  • Tool permissions

  • Escalation thresholds

Example

The LLM can say:

“I can check whether you are eligible for a refund.”

It must not independently decide:

“You are entitled to a £65 refund.”

The refund decision should come from an approved rule or business service.

Amazon’s current customer-service offering explicitly combines generative capabilities for open-ended interactions with deterministic functionality for defined conversational flows, demonstrating that the market is moving towards this mixed model. (Amazon Web Services, Inc.)rchitecture

Customer Channels

Web | Mobile | Voice | Email | WhatsApp | Social

|

API Gateway + WAF + DDoS Protection

|

Identity, Session and Consent Layer

|

AI Policy and Orchestration Layer

| | | |

Intent Safety Journey Model

Router Engine Controller Router

|

Retrieval and Knowledge Layer

Approved content | CRM context | Policies

|

Secure Tool Gateway

|

CRM | Billing | Orders | Payments | Network | Marketing

|

Human Contact-Centre Platform

|

Evaluation | Audit | Observability | Risk | FinOps

Essential architectural principle

The LLM should never have unrestricted access to databases or enterprise APIs.

Every action should pass through a tool gateway that enforces:

  • Identity

  • Authorisation

  • Input schema

  • Output schema

  • Transaction limits

  • Customer consent

  • Data minimisation

  • Rate limits

  • Audit logging

  • Human approval where required

7. Security-first AI design

OWASP identifies prompt injection, sensitive-information disclosure, supply-chain weaknesses, improper output handling, excessive agency and other risks as major threats for LLM applications. The UK NCSC recommends treating security as a lifecycle concern covering design, development, deployment and operation. (OWASP Gen AI Security Project)ls

DomainRequired controls
NetworkWAF, DDoS protection, network segmentation and private endpoints
FirewallDeny-by-default egress and domain/IP allowlists
IdentitySSO, RBAC, ABAC, MFA and privileged-access management
ApplicationsSecure SDLC, dependency scanning, SAST, DAST and API testing
DataEncryption, classification, tokenisation and DLP
ModelsModel approval, version control, red-team testing and rollback
PromptsPrompt versioning, injection testing and policy validation
RetrievalSource allowlists, access-filtered RAG and document sanitisation
ToolsLeast privilege, schema validation and action limits
OutputFact validation, prohibited-content filters and sensitive-data checks
MonitoringSecurity events, AI behaviour, latency, cost and quality
AuditTamper-resistant records of prompts, sources, tools and decisions
Incident responseKill switch, model rollback and customer remediation
SuppliersAI bill of materials, subprocessors and vulnerability obligations

Firewall and connectivity requirements

The production AI service should use:

  • Private connectivity to cloud AI endpoints

  • No unrestricted public internet access

  • Egress allowlisting

  • Separate development, test and production networks

  • Mutual TLS between sensitive services

  • Service mesh or equivalent policy enforcement

  • Controlled DNS resolution

  • Restricted administration networks

  • Central security logging

  • Network intrusion detection

RBAC model

Example roles:

RolePermitted access
CustomerOwn account information only
Service agentAssigned customer cases
Senior agentApproved refunds and escalations
SupervisorTeam monitoring and quality review
Knowledge managerApproved knowledge content
AI product managerPrompts, journeys and metrics
AI engineerTechnical configuration without production PII
Security administratorSecurity controls and investigations
AuditorRead-only audit evidence
Platform administratorInfrastructure, with privileged access controls

MFA

MFA should be mandatory for:

  • Administrators

  • Prompt and policy publishers

  • Knowledge approvers

  • Production support

  • Security investigators

  • Anyone able to change model, tool or access configuration

High-risk customer actions should use step-up authentication even when the customer is already logged in.

8. Prompt-injection and excessive-agency protection

Treat all customer input, retrieved documents, website content and API responses as potentially hostile.

Required controls include:

  • Separate system instructions from customer content.

  • Remove active content from retrieved documents.

  • Prevent retrieved text from changing system permissions.

  • Allow only pre-registered tools.

  • Validate all tool arguments against schemas.

  • Apply transaction and financial limits.

  • Require confirmation before material actions.

  • Require human approval for high-risk actions.

  • Validate tool results before presenting them.

  • Detect unusual sequences of requests.

  • Rate-limit account and data queries.

  • Continuously test known attack scenarios.

9. Cloud, on-premises and hybrid deployment

ModelBest suited toAdvantagesLimitations
Public SaaSStandard service journeysRapid implementation and low infrastructure burdenLess architectural control
Private cloudRegulated enterprise workloadsNetwork, encryption and residency controlGreater operational complexity
HybridMixed-risk multinational environmentsSensitive controls remain private while using advanced cloud modelsIntegration complexity
Fully on-premisesHighly restricted or disconnected environmentsMaximum infrastructure controlGPU cost, skills, patching and model lifecycle burden

For NovaConnect, the strongest option is hybrid private architecture:

  • Customer identity remains in the enterprise identity system.

  • Sensitive records remain in existing systems.

  • Retrieval is security-filtered.

  • Models are accessed using private endpoints.

  • Highly sensitive journeys use private or on-premises models.

  • Billing, payment and account actions remain deterministic.

  • Only the minimum required context is passed to the model.

  • Regional data stores support residency requirements.

When full on-premises is justified

  • Data cannot legally or contractually leave a controlled environment

  • Operations must continue without internet access

  • Interaction volume is large and predictable

  • The organisation can operate GPU infrastructure

  • Latency requirements are extremely strict

  • The model can meet quality expectations

  • There is sufficient security and MLOps capability

On-premises should not be selected only because it sounds more secure. Poorly operated on-premises infrastructure can be less secure than a mature private cloud environment.

10. Compliance and governance

Data-protection requirements

For every processing activity, the organisation should identify:

  • Purpose

  • Lawful basis

  • Data categories

  • Data subjects

  • System recipients

  • Retention period

  • Geographic location

  • Subprocessors

  • Security controls

  • Individual rights

  • Residual risk

The ICO states that organisations must separate distinct AI processing operations and identify an appropriate purpose and lawful basis for each. It also provides an AI and data-protection risk toolkit. (ICO)cts

  • Data Protection Impact Assessment

  • AI impact assessment

  • Data-flow diagram

  • Records of processing activities

  • Legitimate interests assessment where applicable

  • Model card

  • System card

  • Dataset documentation

  • AI risk register

  • Security threat model

  • Human-oversight procedure

  • Retention and deletion policy

  • Incident-response plan

  • Vendor/subprocessor register

  • AI system inventory

  • Customer transparency notice

  • Accessibility assessment

  • Equality and fairness testing

  • Business-continuity plan

Customer transparency

The customer should understand:

  • That they are interacting with AI

  • What the AI can and cannot do

  • When personal data is being used

  • How to reach a human

  • How to challenge an outcome

  • How conversation data may be retained

  • How to exercise data-protection rights

Global deployment model

RegionPrimary product consideration
UKUK GDPR, ICO expectations, accessibility and consumer protection
EU/EEAGDPR, EU AI Act transparency and country-specific requirements
North AmericaState, federal and sector-specific requirements
Middle EastData residency, Arabic support and local hosting expectations
Asia-PacificLocal-language quality, data residency and messaging-channel integration
Latin AmericaSpanish/Portuguese localisation and cost-efficient digital service
AfricaMobile-first interfaces, bandwidth efficiency and language coverage

The product should use a global core with local compliance and language packs, rather than building a completely different platform for every country.

11. Current market state

The market is moving through four stages:

  • Rule-based FAQ bots

  • Generative knowledge assistants

  • Transaction-capable AI agents

  • Orchestrated human-and-AI customer operations

McKinsey’s 2025 global survey found that 23% of respondents reported scaling an agentic AI system somewhere in their enterprise. This indicates strong momentum, but also shows that mature, scaled adoption is not yet universal. (McKinsey & Company)timate valued the AI-for-customer-service market at approximately $13 billion in 2024 and forecasts it could reach about $84 billion by 2033. Such forecasts should be treated directionally rather than used as a financial business-case assumption. (Grand View Research)t realities

AI is becoming a standard platform capability

Salesforce, Microsoft, AWS, Google, ServiceNow, Zendesk and Fin now offer customer-service agents, agent assistance, workflow automation or omnichannel AI within their wider platforms. (Microsoft)nging

Current commercial models include:

  • Per user

  • Per conversation

  • Per successful outcome

  • Per request

  • Per voice minute

  • Credits or consumption

  • Enterprise commitments

For example, Fin currently advertises $0.99 per successful outcome. Salesforce offers consumption, credit and per-user approaches, while AWS and Google publish usage-based channel or conversational-agent pricing. (Intercom)ion is not automatic

Research on chatbot adoption found that customers may avoid systems perceived as gatekeepers. Transparency about capabilities, showing expected waiting times and enabling faster access to humans after AI failure can improve adoption. (arXiv)ce can create value before autonomy

A 2026 field experiment in Alibaba’s customer-service operations found improvements in service speed and subjective service quality, although the benefits differed by agent performance level. This supports beginning with agent assist and controlled automation instead of immediately pursuing complete autonomy. (arXiv)tor analysis

Competitor categoryStrengthBest fitBuyer consideration
Salesforce AgentforceDeep CRM, service and customer-data integrationSalesforce-led enterprisesLicensing, implementation complexity and ecosystem dependency
Microsoft Dynamics/CopilotMicrosoft integration, low-code tools and enterprise identityMicrosoft-oriented organisationsProduct and licensing architecture must be carefully designed
AWS ConnectCloud contact centre, usage pricing and deterministic/AI combinationAWS-native enterprisesRequires strong cloud and integration capability
Google Customer EngagementConversational AI, voice, multimodal and analyticsGoogle Cloud and AI-focused organisationsEnterprise integration and commercial structure require assessment
ServiceNow CSMWorkflow and service-operation automationProcess-heavy enterprisesStrongest where ServiceNow is already strategic
ZendeskIntegrated support suite and AI-agent capabilityMid-market and service-led businessesDeep enterprise customisation must be validated
FinFast customer-service focus and outcome pricingDigital service companiesComplex on-premises and regulated use cases require careful evaluation
Custom platformMaximum control and differentiationLarge regulated enterprisesHigher build, support and talent requirements

Official product materials show the industry converging around omnichannel service, autonomous workflows, agent assistance, summaries and CRM integration. (Google Cloud)market segment

Do not target “every company that needs a chatbot.”

Regulated, service-intensive enterprises with complex customer journeys and more than one million annual interactions.

Priority sectors:

  • Telecommunications

  • Banking and insurance

  • Utilities

  • Healthcare administration

  • Travel

  • Government services

  • Large subscription businesses

  • Enterprise retail and e-commerce

Buyer characteristics

  • Existing CRM and contact-centre investment

  • Multiple customer channels

  • High operational service cost

  • Sensitive personal data

  • Strict audit requirements

  • Several countries or languages

  • Significant legacy-system integration

  • Need for human escalation

  • Concerns about vendor lock-in

14. Unique value proposition

A security-first customer-resolution platform that combines generative conversation with deterministic enterprise workflows, providing verifiable answers, controlled actions and seamless human escalation across cloud, private and on-premises environments.

Core differentiators

1. Resolution, not conversation

Measure successful customer outcomes rather than chatbot engagement.

2. Deterministic transaction core

The AI explains and orchestrates, but approved systems calculate, decide and execute.

3. Evidence-backed responses

Every material response can be linked to:

  • Approved source

  • Policy version

  • Customer record

  • Tool result

  • Decision rule

4. Security and compliance by design

Security is part of the architecture and commercial offering, not an optional implementation workstream.

5. Hybrid and vendor-neutral deployment

Support multiple models and deployment environments.

6. Journey-level evaluation

Test whether a complete customer need was resolved, not merely whether an answer sounded fluent.

7. Safe human collaboration

Human escalation is a product capability, not a failure.

8. Global core, local controls

Localise:

  • Language

  • Data residency

  • Regulatory disclosures

  • Product catalogues

  • Escalation rules

  • Cultural tone

15. Product-market fit

Customer job to be done

“Help my organisation resolve more customer needs quickly and safely without increasing contact-centre cost at the same rate as customer demand.”

Buyer pain

  • High cost per contact

  • Poor system integration

  • Low trust in generative AI

  • Inconsistent answers

  • Weak auditability

  • Failed chatbot implementations

  • Agent resistance

  • Vendor lock-in

  • Inability to demonstrate ROI

PMF hypotheses

HypothesisValidation method
Customers will use AI when it resolves needs fasterA/B test uptake and completion
Enterprises will pay for verifiable resolutionPaid proof of value
Security is a buying differentiatorWin/loss interviews
Hybrid deployment increases regulated-sector demandRFI and discovery analysis
Outcome pricing reduces buying frictionCommercial experiments
Human handoff improves trustCSAT and abandonment comparison

Product-market-fit signals

  • More than 60% of pilots convert to production

  • Customers expand to additional journeys

  • Reference customers are willing to speak publicly

  • Gross revenue retention exceeds 90%

  • Customers achieve payback within 12–18 months

  • Successful resolution improves without reducing CSAT

  • Implementation time consistently decreases

  • Security reviews become repeatable rather than bespoke

  • Product usage expands beyond the original team

16. Business and commercial model

A B2B enterprise SaaS and managed-service model.

Revenue streams

  • Platform subscription

  • Successful-resolution usage

  • Agent-assist licences

  • Implementation and integration

  • Private-cloud or on-premises licence

  • Managed AI operations

  • Governance and compliance package

  • Premium multilingual support

  • Analytics and optimisation

  • Training and change management

Base platform fee

Covers:

  • Core platform

  • Administration

  • Security

  • Standard integrations

  • Analytics

  • Governance controls

  • Support

Outcome fee

Charged when:

  • The customer’s issue is successfully resolved

  • No human intervention is required within a defined period

  • The action is completed correctly

  • The interaction meets quality thresholds

Professional services

Charged for:

  • Journey design

  • Data preparation

  • Integration

  • Security review

  • Migration

  • Custom models

  • Change management

Managed service

Recurring charge for:

  • Model monitoring

  • Prompt optimisation

  • Evaluation

  • Knowledge quality

  • Incident management

  • Cost optimisation

  • Regulatory updates

Commercial guardrails

Define “successful resolution” contractually. It must not mean merely that the customer stopped responding.

A valid resolution could require:

  • Confirmed completion

  • No repeat contact within seven days

  • No related complaint

  • No human reopening

  • Minimum quality score

  • Correct completion of the transaction

17. Illustrative financial business case

Current state

AssumptionValue
Annual contacts5,000,000
Average cost per contact£4.20
Annual service cost£21,000,000

Expected operating case

DriverAssumption
Contacts eligible for AI self-service55%
Customer uptake75%
Successful AI resolution68%
AI-resolved contacts1,402,500
Avoided cost per resolved contact£3.40
Gross service saving£4.77m
Realised agent-assist saving£1.09m
Incremental contribution from sales£1.20m
Contribution from churn reduction£0.80m
Annual platform and operating cost£3.10m
Initial implementation£3.80m

Results

  • Annual gross benefit: approximately £7.86 million

  • Annual net benefit: approximately £4.76 million

  • Indicative payback: approximately 9.6 months

  • Illustrative three-year ROI: approximately 80%

These are planning assumptions, not guaranteed results. Each number must be validated during discovery and pilot.

Unit economics per resolved interaction

ComponentIllustrative amount
Avoided human-service cost£3.40
AI model and platform variable cost£0.18
Quality and governance allocation£0.12
Operational support allocation£0.10
Contribution per AI resolution£3.00

The most important metric is:

Contribution per successful resolution, not cost per token.

18. AI energy and environmental cost

AI energy should be managed as part of FinOps and GreenOps.

Data-centre electricity demand increased significantly during 2025, and the IEA projects global data-centre electricity consumption could reach approximately 945 TWh by 2030 in its base case. (IEA)ergy and cost

  • Model size

  • Number of tokens

  • Context length

  • Voice processing

  • Repeated retrieval

  • Multiple model calls

  • Low GPU utilisation

  • Always-on capacity

  • Data transfer

  • Vector search

  • Evaluation workloads

  • Excessive logging

  • Cooling and infrastructure overhead

Metrics to monitor

  • Tokens per resolved case

  • Model calls per interaction

  • kWh per 1,000 interactions

  • Carbon emissions per 1,000 interactions

  • Cost per successful resolution

  • GPU utilisation

  • Cache-hit rate

  • Average context size

  • Model-routing distribution

  • Percentage of failed or repeated calls

Optimisation methods

  • Route simple tasks to smaller models

  • Use deterministic rules where appropriate

  • Cache common responses

  • Reduce retrieved context

  • Summarise long histories

  • Limit response length

  • Batch offline evaluation

  • Quantise self-hosted models

  • Scale infrastructure with demand

  • Select efficient hosting regions

  • Track environmental cost alongside financial cost

Do not use a universal “energy per AI question” estimate. Actual consumption depends heavily on model, hardware, utilisation, response length and hosting architecture.

19. Sales funnel

Enterprise sales funnel

StageBuyer activitySeller objective
AwarenessRecognises service-cost or CX problemEstablish category credibility
InterestDownloads report or attends eventQualify industry and pain
DiscoveryShares volumes, systems and objectivesQuantify business case
Solution workshopMaps customer journeysAgree priority use cases
Technical validationReviews security and integrationRemove architecture objections
Proof of valueTests limited journeysDemonstrate measurable value
Business caseReviews ROI and operating modelSecure executive sponsorship
ProcurementRuns RFP and due diligenceAchieve preferred-vendor status
NegotiationAgrees legal and commercial termsProtect margin and manage risk
ImplementationDeploys initial use casesAchieve time to value
ExpansionAdds journeys and countriesIncrease annual contract value

Funnel qualification

Use MEDDPICC or an equivalent enterprise framework:

  • Metrics

  • Economic buyer

  • Decision criteria

  • Decision process

  • Paper process

  • Identified pain

  • Champion

  • Competition

Key buyer personas

  • Chief Operating Officer

  • Chief Customer Officer

  • Chief Information Officer

  • Chief Digital Officer

  • Customer Service Director

  • Contact Centre Director

  • Chief Information Security Officer

  • Data Protection Officer

  • Head of AI

  • Procurement Director

  • Chief Financial Officer

20. Marketing strategy

Positioning themes

Theme 1: Trusted resolution

“Give customers correct outcomes, not just fluent answers.”

Theme 2: Controlled autonomy

“Automate safely with deterministic controls and human oversight.”

Theme 3: Business economics

“Reduce cost per resolution while protecting customer satisfaction.”

Theme 4: Enterprise integration

“Connect AI to the systems where customer work actually happens.”

Theme 5: Regulatory readiness

“Operate with evidence, accountability and auditability.”

Marketing assets

  • Executive AI customer-service benchmark

  • ROI calculator

  • Security architecture paper

  • Regulatory readiness guide

  • Industry-specific demonstrations

  • Customer journey assessment

  • RFP template

  • AI-resolution maturity assessment

  • Reference architectures

  • Case studies

  • Executive roundtables

  • Security and compliance workshops

21. Go-to-market strategy

Phase 1: Beachhead

Target UK-regulated or service-intensive enterprises with:

  • More than one million annual contacts

  • High average handling cost

  • Existing cloud or CRM transformation

  • Executive AI sponsorship

  • Clear pain in billing, account or order enquiries

Lead with two or three repeatable journeys:

  • Billing explanation

  • Order or service status

  • Account and plan management

Phase 2: Verticalisation

Develop industry packs:

  • Telecom customer service

  • Banking service

  • Utilities billing

  • Insurance claims support

  • Travel disruption

  • Healthcare administration

Each pack contains:

  • Journey templates

  • Security controls

  • Evaluation sets

  • Data mappings

  • Regulatory controls

  • Integration patterns

  • KPI benchmarks

Phase 3: Geographic expansion

Expand using:

  • Regional implementation partners

  • Local-language packs

  • Cloud-marketplace listings

  • Data-residency options

  • Local regulatory mappings

  • Regional customer references

Phase 4: Platform expansion

Move from service into:

  • Sales

  • Retention

  • Marketing

  • Employee service

  • Field service

  • Partner support

  • Customer-success operations

22. Procurement process

UK government AI procurement guidance recommends structured preparation, supplier evaluation, selection, contracting and ongoing management. Similar discipline is valuable in private-sector enterprise procurement. (GOV.UK)efinition

Produce:

  • Problem statement

  • Contact-volume baseline

  • Customer journeys

  • Target outcomes

  • Budget range

  • Risk appetite

  • Data classification

  • Deployment constraints

Stage 2: Market engagement

Use:

  • Request for Information

  • Supplier demonstrations

  • Architecture workshops

  • Reference calls

  • Market benchmarking

Stage 3: RFP

Request evidence for:

  • Business outcomes

  • Security

  • Privacy

  • AI quality

  • Integration

  • Scalability

  • Availability

  • Accessibility

  • Data residency

  • Model flexibility

  • Exit and portability

  • Total cost

  • Sustainability

Stage 4: Technical and security assessment

Require:

  • Penetration-test evidence

  • Security certifications

  • Data-flow diagrams

  • Subprocessor list

  • Incident history

  • Encryption design

  • Identity model

  • Model-provider arrangements

  • Logging and retention

  • Disaster recovery

  • Secure development process

  • Prompt-injection testing

Stage 5: Proof of value

The proof should use:

  • Realistic anonymised data

  • Defined acceptance criteria

  • Known edge cases

  • Security testing

  • Customer-experience testing

  • Performance and cost measurement

Stage 6: Commercial negotiation

Negotiate:

  • Pricing metric

  • Volume commitments

  • Service levels

  • Data ownership

  • Model-training restrictions

  • Subprocessor changes

  • Liability

  • Security incidents

  • Audit rights

  • Exit support

  • Data deletion

  • Benchmarking rights

Stage 7: Contract implementation

Create:

  • Implementation plan

  • Acceptance tests

  • Governance calendar

  • KPI dashboard

  • Incident process

  • Change-control process

  • Exit plan

Suggested procurement weighting

CriterionWeight
Business and journey fit20%
Security and compliance20%
AI quality and evaluation15%
Integration and architecture15%
Total cost and unit economics10%
Operability and support10%
Supplier viability5%
Commercial flexibility and exit5%

23. Prioritisation method

Use a risk-adjusted scoring model.

Score each use case from one to five.

CriterionWeight
Financial value20%
Customer impact15%
Contact volume15%
Technical feasibility15%
Data readiness10%
Strategic fit10%
Time to value10%
Risk suitability5%

Example prioritisation

Use caseValueFeasibilityRiskPriority
Order statusHighHighLow1
Bill explanationHighHighMedium2
Password/account helpMediumHighMedium3
Network troubleshootingHighMediumMedium4
Plan recommendationHighMediumMedium5
Complaint resolutionHighMediumHighLater
Refund approvalHighMediumHighLater
Credit decisionHighLowVery highExclude initially

Stage-gate rule

No journey should move to production unless it passes:

  • Business-value gate

  • Data-readiness gate

  • Security gate

  • Privacy and compliance gate

  • Offline evaluation gate

  • User-acceptance gate

  • Production-readiness gate

24. Product and business roadmap

Months 0–3: Foundation

  • Executive sponsor and business owner

  • Customer-service baseline

  • AI inventory

  • Target operating model

  • DPIA and threat model

  • Architecture decision

  • Knowledge assessment

  • Vendor assessment

  • Evaluation framework

  • Employee consultation

  • Pilot journey selection

Months 4–6: Controlled pilot

Deploy:

  • Order status

  • General product information

  • Basic bill explanation

  • Human handoff

  • Agent summaries

  • Quality dashboard

Pilot with 5–10% of digital traffic.

Months 7–9: Transactional service

Add:

  • Authenticated account access

  • Payment support

  • Plan changes

  • Service diagnostics

  • CRM integration

  • Personalised recommendations

  • Multilingual journeys

Months 10–12: Operational scale

Add:

  • Voice

  • Email automation

  • Supervisor analytics

  • Proactive outage communication

  • Workforce forecasting

  • Automated quality evaluation

  • Regional deployment

Months 13–18: Competitive differentiation

Add:

  • Predictive service

  • Churn intervention

  • Customer digital twin/context

  • Multi-agent orchestration

  • Advanced journey personalisation

  • Partner ecosystem

  • Outcome-based commercial optimisation

  • Private/on-premises deployment package

25. Governance structure

NIST’s AI Risk Management Framework organises AI risk activities around Govern, Map, Measure and Manage, which provides a useful structure for the governance model. (NIST)tive governance

Board or Risk Committee

  • Approves risk appetite

  • Reviews material customer and regulatory risk

  • Challenges strategic investment

  • Monitors major incidents

Executive AI Steering Committee

  • Prioritises investment

  • Approves scale decisions

  • Resolves cross-functional issues

  • Reviews value, risk and adoption

AI Product Council

  • Approves journeys

  • Reviews product performance

  • Manages roadmap

  • Coordinates business functions

AI Risk and Assurance Forum

  • Security

  • Privacy

  • Legal

  • Compliance

  • Model risk

  • Internal audit

  • Customer conduct

26. Key stakeholders

StakeholderAccountability
CEOStrategic sponsorship and outcome
Chairman/BoardOversight and risk challenge
COOCustomer-operations transformation
Chief Customer OfficerCustomer experience
CFOBusiness case and benefit realisation
CIO/CTOTechnology and integration
Chief Digital OfficerDigital journey and adoption
CISOCybersecurity
DPOData protection
General CounselLegal and contractual risk
Chief Risk OfficerEnterprise risk
CMOBrand, customer communication and consent
Sales DirectorConversion and commercial journeys
Customer Service DirectorOperational ownership
Contact Centre DirectorWorkforce and delivery
Head of AIAI strategy, standards and capability
AI Product OwnerDay-to-day product accountability
Data OwnerData quality and access
Knowledge ManagerApproved knowledge
ProcurementSupplier sourcing and contract
HR/PeopleWorkforce impact and change
Internal AuditIndependent assurance
Employee representativesWorkforce consultation
Customer advisory groupUser feedback and accessibility

Who should be the customer-side AI lead?

There are two different roles:

Executive AI sponsor

Usually one of:

  • CIO

  • CDO

  • CTO

  • COO

  • Chief Customer Officer

This person owns executive alignment and funding.

Delivery AI lead

Usually:

  • Head of AI

  • Director of AI

  • AI Transformation Lead

  • AI Product Director

  • Enterprise AI Architect

The delivery AI lead should not own the business outcome alone. The Customer Service Director or Chief Customer Officer should remain accountable for the customer-service result.

27. Adoption policy

Employees may

  • Use approved AI systems

  • Review AI recommendations

  • Correct incorrect outputs

  • Report harmful or inaccurate results

  • Use AI-generated summaries after validation

  • Use approved customer and company data within policy

Employees must not

  • Enter data into unapproved public AI tools

  • Allow AI to make unauthorised financial decisions

  • bypass human approval controls

  • Share credentials with AI systems

  • Treat AI output as automatically correct

  • Change production prompts without approval

  • Conceal an AI-related incident

  • Use customer conversations for unrelated purposes

28. Change management

Change principles

Explain the purpose

Position AI as:

  • Removing repetitive work

  • Improving customer resolution

  • Supporting employee judgement

  • Reducing system switching

  • Creating capacity for complex cases

Involve agents early

Agents should participate in:

  • Journey design

  • Evaluation

  • Failure analysis

  • Knowledge improvement

  • Interface testing

  • Escalation design

Redesign performance measures

Do not punish agents because AI handles easier cases and leaves them with more complex conversations.

Review:

  • Average handling time targets

  • Quality scoring

  • Productivity expectations

  • Sales targets

  • Escalation targets

  • Training requirements

Training

Provide:

  • AI literacy

  • Security and privacy

  • Correct use

  • Limitations

  • Escalation

  • Customer transparency

  • Incident reporting

  • Bias and fairness

  • Prompt-injection awareness

29. Risk register

RiskLikelihoodImpactPrimary control
Incorrect customer answerMediumHighGrounded responses and evaluation
Personal-data leakageMediumCriticalDLP, access control and minimisation
Prompt injectionHighHighTool isolation and input controls
Unauthorised transactionLowCriticalDeterministic policy and approval
Customer cannot reach humanMediumHighExplicit escalation paths
Discriminatory treatmentLow/MediumHighFairness testing and monitoring
Low customer adoptionMediumMediumTransparency and channel choice
Agent resistanceMediumHighCo-design and change management
Vendor lock-inMediumHighPortability and exit clauses
Unexpected AI costMediumHighModel routing and FinOps
Service outageMediumHighResilience and fallback
Knowledge becomes outdatedHighHighContent ownership and expiry
Regulatory changeMediumHighCompliance monitoring
Reputational incidentLow/MediumCriticalIncident response and communication
Claimed savings not realisedMediumHighFinance-led benefit tracking

30. “Where are we?” versus “What must be implemented?”

Representative gap analysis

AreaTypical current positionRequired target
Customer experienceFAQ chatbotEnd-to-end resolution
ChannelsWeb chat onlyOmnichannel
KnowledgeUnstructured documentsGoverned knowledge products
IntegrationLimited CRM lookupSecure transactional APIs
IdentityAnonymous conversationsIdentity-aware service
Decision-makingLLM-generated answersDeterministic policy engine
SecurityStandard application controlsAI-specific threat model
AccessBroad service accountsRBAC, ABAC and least privilege
AdministrationPassword-basedSSO, MFA and privileged access
NetworkPublic endpointsPrivate connectivity and allowlisting
Data protectionGeneral privacy policyJourney-level DPIA and minimisation
EvaluationManual spot checksAutomated and human evaluation
MonitoringUptime and errorsQuality, risk, cost and customer outcomes
GovernanceProject steering groupEnterprise AI operating model
OwnershipTechnology-ledBusiness-product ownership
FinancialsTechnology budgetBenefit and unit-economics tracking
DeploymentOne marketGlobal core with local controls
FeedbackCSAT onlyClosed-loop journey improvement
ChangeTool trainingWorkforce and process redesign
Commercial modelLicence focusedOutcome and value based

31. Immediate implementation priorities

Priority 1: Establish the business baseline

Measure:

  • Contact volume

  • Cost per contact

  • Repeat contacts

  • Resolution rate

  • Customer satisfaction

  • Average handling time

  • Top customer intents

  • Escalation rate

  • Complaint rate

  • Revenue and churn influence

Priority 2: Select three journeys

Recommended:

  • Order or service status

  • Billing explanation

  • General account support

Priority 3: Establish security and governance

Create:

  • AI policy

  • AI inventory

  • DPIA

  • Threat model

  • Risk register

  • Model approval process

  • Evaluation standards

  • Incident process

Priority 4: Build the deterministic service layer

Prioritise APIs for:

  • Identity

  • Account

  • Billing

  • Orders

  • Payments

  • Product eligibility

  • Escalation

Priority 5: Create the evaluation system

Test:

  • Correctness

  • Groundedness

  • Resolution

  • Safety

  • Privacy

  • Tool use

  • Escalation

  • Fairness

  • Latency

  • Cost

Priority 6: Pilot with humans in control

Start with agent assistance and low-risk self-service, then increase autonomy only when evidence supports it.

32. Final CEO and Chairman briefing

We propose creating a security-first AI customer-resolution platform rather than deploying another standalone chatbot. The platform will combine conversational AI with deterministic business systems, allowing customers to receive immediate answers and complete approved actions while preserving human access for complex, vulnerable or regulated situations.

The initial business case indicates the potential to resolve approximately 1.4 million annual interactions through AI, generate around £7.9 million in annual gross benefit and achieve an indicative payback period of approximately ten months. These assumptions will be validated through a controlled pilot.

Our competitive advantage will come from verifiable resolution, controlled autonomy, secure enterprise integration, hybrid deployment and journey-level governance. We recommend beginning with billing explanation, order status and account support, followed by transactional services, voice, retention and proactive support.

The executive decision required is approval for the discovery and pilot programme, appointment of an accountable customer-service business owner, establishment of the AI governance structure and agreement on the financial, customer, security and compliance success criteria.

The strongest strategic framing is:

Not a chatbot. A secure customer-resolution operating model powered by AI.

Discussion

Comments

Share feedback or questions about this page. No account required.

Loading comments…