Executive summary
A third of enterprises have already deployed AI agents. Almost none have reached full production, and it’s not a technology problem. Integration and orchestration, the two things every vendor deck claims to solve, were never built to answer the question that matters in regulated CX: who approved this action, where’s the record. This piece breaks down why that gap is structural, and what closes it.
35%. That’s how many enterprises have already deployed AI agents somewhere in the business, per MIT Sloan and BCG’s latest data. Here’s what the vendor decks don’t lead with: only a fraction of that group has gotten those agents running at full scale. Sit with that gap for a second — a third of the market has agents live, and barely one in ten has cracked how to run them for real.
If you work in regulated CX, you already know why. It’s not the AI. It’s everything around AI.
A March 2026 Harvard Business Review study by Karim Lakhani (Harvard Business School), Jared Spataro (Microsoft), and Jen Stave (Harvard’s Digital, Data & Design Institute) calls this the “last mile” problem, and it’s the sharpest framing I’ve seen for what’s actually happening on the ground.
Their argument: the primary obstacle to closing the gap is rarely model quality or data availability. It’s the gap between technical capability and organizational design. Companies pilot hundreds of use cases, get real wins in isolated pockets, and still can’t get any of it to show up at the enterprise level.
A few numbers from their research that stuck with me:
- One global investment bank built 250+ LLM-connected applications. Every gain stayed localized: none of it scaled.
- One global payments network hit 99% employee adoption of Copilot company-wide, and still couldn’t point to a single measurable gain in efficiency or cycle time.
- One asset-servicing firm is already running 100+ AI agents and is planning to scale into the tens of thousands, without losing control of accountability and compliance.
Two of the seven frictions the authors name are the ones that should make every regulated CX leader sit up: architectural complexity (multi-vendor stacks need heavy engineering just to get systems talking) and agentic governance gaps (even when they do talk, nobody’s built the layer that governs what happens once agents start acting on their own).
That second one is the whole ballgame. It’s not an integration problem. It’s not even an orchestration problem. It’s an execution problem — and in regulated industries, it’s the one you genuinely cannot skip.
Three Layers, Not Two
Here’s where I think most of the industry conversation gets sloppy. “Integration” and “orchestration” get used like synonyms in vendor decks, and that’s not a small mistake.
It’s the mistake.
The Layer Neither One Touches
This isn’t a borrowed framework. It’s the distinction NovelVox has built its entire architecture around, because it’s the one regulated CX actually runs on:
- Integration connects systems. It moves data between two points. Plumbing.
- Orchestration coordinates capabilities into a business process, without embedding business logic into the connection itself. Choreography.
- Execution is the layer neither one touches: proof that an action was authorized, logged, and defensible after the fact.

In banking, credit unions, and healthcare, that third layer is the one regulators actually test for.
Why Regulated CX Breaks Differently
A generic orchestration layer can route a request, trigger a workflow, and hand off between systems flawlessly. And still have zero answer for the question a bank examiner or a HIPAA auditor is going to ask:
- Who approved this action
- Under what policy, and
- Where’s the record?
Three regulatory pressures are converging on exactly that demand right now:
- EU AI Act, Article 50: transparency obligations for AI systems interacting with people.
- US financial services: fast-mounting compliance pressure specifically around agentic systems acting on customer accounts.
- HIPAA: audit-trail requirements for any automated action touching patient data.
An orchestration platform built for general enterprise workflows treats traceability as an afterthought, if it treats it at all. Here’s the part worth saying plainly: a contact center running ungoverned agentic workflows in banking or healthcare isn’t ahead of the curve. It’s carrying compliance risk it hasn’t priced in yet.
The market’s already sensing this shift, even if the language isn’t fully settled. Vendors across the space are starting to talk about unifying agent workflows and cutting friction across the customer journey — real signal that the industry independently arriving at the same instinct. But orchestration alone still doesn’t answer the audit question. It coordinates the action. It doesn’t govern it.
What this means for SI/CCaaS vendors: The execution gap is your liability too, not just your customer’s. A project that ships without governed execution leaves you holding the risk when a client fails an audit. The fix isn’t rebuilding your integration or orchestration stack. It’s adding the layer that was always missing on top of it.
Execution is the Governance Layer, Not the Compliance Tax
Here’s the instinct I want to push back on directly: treating governance as friction, as a checkpoint that slows execution down. It’s backwards. Ungoverned orchestration is what actually creates delay — every autonomous action without a traceable authorization chain becomes a liability someone has to manually untangle later, usually after something’s already gone wrong.
| Download Case Study: How a Leading U.S. Bank Enabled Secure, Transaction-Ready Self-Service With CCIP |
A real execution layer doesn’t sit on top of orchestration as overhead. It’s what makes orchestration safe to run at full speed in a regulated environment:
- A well-built execution layer means every agent action carries its authorization with it. It is built to each institution’s own policy requirements, not delivered as a one-size-fits-all default.
- Handoffs can be logged before they happen, rather than reconstructed after the fact, when the workflow is built to require it.
- Enforcement can be built into the action itself, rather than bolted on as a review step, depending on how the execution layer is configured.
Integration got the industry connected. Orchestration got it coordinated. The institutions that pull ahead from here won’t be the ones with the most agents deployed — they’ll be the ones that can prove, on demand, that every action those agents took was authorized, traced, and defensible. In regulated CX, that’s not a compliance feature. It’s the only version of fast that survives an audit.
If your stack is strong on integration, strong on orchestration, and still can’t answer the audit question — that’s exactly the gap NovelVox was built to close. CCIP brings integration, orchestration, and execution together as one governed layer, purpose-built for regulated CX.
NovelVox has spent 17+ years building for exactly this: CMMi Level 3, a Jack Henry VIP Partner since 2018, and trusted across 250+ customers in regulated CX.
Worth a conversation if your stack can already talk to everything it needs to, and still can’t answer for what it did. Connect with Us.










