Conversational AI is already moving into mainstream customer service, with Gartner predicting that by 2028, at least 70% of customers will use a conversational AI interface to start their customer service journey.
But in regulated industries like healthcare, finance, utilities and telecommunications, there’s still a fair amount of hesitation when it comes to adopting the latest technology.
These organisations handle sensitive information and support customers through situations where poor advice or a badly designed journey could have serious consequences.
However, being careful doesn’t have to mean standing still. When conversational AI is designed around clear responsibilities, appropriate controls and good customer outcomes, it can improve access to support while maintaining the protections customers rely on.
Here are five common misconceptions we hear, and what organisations should consider instead.
1. “Conversational AI can’t be compliant”
There is no single UK rule that prevents regulated organisations from using conversational AI. Instead, existing sector regulation continues to apply, and AI needs to be designed within those boundaries.
Those expectations differ by sector:
- Financial services: The FCA’s Consumer Duty requires firms to deliver good outcomes across communications and support, with senior managers remaining accountable for how new technologies are governed and deployed.
- Telecommunications: Ofcom guidance on vulnerable customers requires providers to identify and support customers who may be at risk of harm or disadvantage.
- Energy: Ofgem’s approach to AI focuses on fair outcomes, transparency and strong governance when AI is introduced into customer-facing services.
- Healthcare: The CQC’s expectations on AI emphasise safe, equitable and person-centred care, while NHS guidance also places importance on information governance and data protection
The common thread is that AI doesn’t sit outside the existing rulebook.
Compliance starts with the customer journey, not the technology. Organisations need to understand the outcome the AI is supporting, the information it requires and the point at which responsibility should return to a person.
Defining those boundaries first makes it easier to choose the right technology, controls and escalation points. That is the foundation of a compliance-first approach.
2. “It’s just a chatbot, so it isn’t worth the effort”
Older chatbots haven’t always helped the reputation of conversational AI, with many relying on fixed scripts and simple keyword matching.
While that makes their responses easier to control, the experience can quickly fall apart when a customer phrases something differently or needs help with more than one step.
Modern conversational AI is much more capable. It can understand intent and sentiment behind a customer’s words, retain context and draw information from approved knowledge sources. When connected securely to contact centre systems, it can also support more involved enquiries instead of simply directing customers towards a webpage.
This can make customer service available around the clock for routine needs, without forcing people through a rigid menu. Customers receive quicker support, and agents have more time for interactions involving vulnerability or professional judgement.
3. “AI has to manage the whole customer journey”
One of the biggest concerns for regulated organisations is that introducing conversational AI means handing over too much control, but this doesn’t have to be the case.
In regulated environments, a more practical approach is to assess each stage according to its purpose and risk. AI might provide approved information, authenticate a customer or collect initial details, while a person takes over when judgement, vulnerability or a significant decision is involved.
This is especially important where a conversation involves vulnerability, sensitive information or a decision that could significantly affect the customer. In these situations, organisations need to maintain meaningful human oversight rather than relying on automation.
These boundaries should be decided before implementation. Teams need to agree when the AI must escalate the interaction and what information should follow into the human conversation.
4. “Using conversational AI means losing control of customer data”
Data is one of the biggest concerns for any organisation exploring AI, and rightly so.
There is, however, an important difference between entering customer information into a public AI service and implementing an enterprise solution designed around the organisation’s own security requirements.
UK GDPR and the Data Protection Act 2018 still apply when personal information is processed through AI. Organisations need an appropriate lawful basis for processing personal information, transparency about how it’s being used and controls that limit access to what is necessary.
This is especially important where special category data is involved, such as health information. Other sectors may handle financial details or information revealing that a customer is vulnerable. In every case, access should reflect what the AI actually needs rather than what is technically available.
Before implementation, organisations should understand how conversations move between the AI platform and their existing systems. Supplier arrangements need to make clear where information is processed, how long it is retained and whether it can be used to train a wider model.
A Data Protection Impact Assessment may be needed for higher-risk processing. More importantly, carrying one out early can uncover design problems before they become expensive to fix.
5. “Generative AI is too unpredictable for regulated use”
This concern often comes from treating conversational AI as a choice between a rigid scripted bot and an unrestricted generative model.
But there’s another option available.
Deterministic AI or automation follows predefined rules, approved responses and structured paths, making it useful where consistency and control are particularly important.
Generative AI provides greater flexibility, allowing interactions to adapt to natural language and context. When grounded in approved knowledge and surrounded by suitable guardrails, it can provide a more natural experience without being given unrestricted freedom.
For many regulated journeys, the answer will be a combination of the two.
Higher-risk stages can remain tightly controlled, while generative AI provides flexibility in lower-risk parts of the conversation. When an interaction moves outside defined boundaries, detects a risk signal or requires human judgement, it can be escalated to an agent.
Data protection controls also need to support, rather than undermine, the customer experience. Many leading solutions can redact personal identifiable information to reduce privacy risk before data is passed to a third-party LLM. However, removing too much context can affect how well the AI understands the conversation.
The goal should be to find the right balance between protecting sensitive information and preserving enough context for the system to remain useful.
Taking the first step
Introducing conversational AI is not something organisations should rush into. It needs careful planning, clear boundaries and the right support around it.
With an experienced partner, however, it can make a real difference to both customers and contact centre teams. SVL can help you identify where conversational AI will add the most value and shape an approach that fits your regulatory responsibilities.
Get in touch with our team to discuss the right next step for your contact centre.