Most conversations about AI in the contact center focus on the customer experience layer: bigger queues handled by smaller teams, agents augmented instead of replaced, customers routed by intent instead of button-mashing through an IVR tree. The contact center world runs on average handle time and CSAT. Different vocabularies, same house: cybersecurity is simply further along on the blueprint.
That idea, that identity is the new edge, was the center of a recent episode of the Amplitude of Tech podcast, in conversation with Brian Zimmer, Field CISO at CyberMaxx, who has spent more than two decades building security programs across system administration, pre-sales, and executive leadership roles. Zimmer walked through why credential-based attacks have become the attacker’s cheapest, most reliable playbook, and why identity governance, done right, actually removes the friction security teams have long assumed was mandatory. If that’s true for a corporate network, it’s doubly true for a contact center.
| Quick Answer: Cybersecurity replaced the network perimeter with identity as the control point years ago. Contact centers are living the same shift today, across voice, chat, and a growing number of AI agents acting on customers’ behalf. The fix in both worlds is identical: minimize friction for the real user, maximize it for the attacker, and govern every AI agent identity with the same rigor as a human employee’s. |
The Castle Is Gone, and So Is the Front Door
There is the old model of enterprise security: the castle-and-moat approach, where the perimeter was a physical building, a handful of locations, a network you could actually draw a line around. Remote work, then COVID, then a fleet of personal devices and IoT gadgets blew that perimeter apart. The wall isn’t the edge anymore. The user is.
Swap “network” for “contact center” and the story is nearly identical. Ten years ago, the attack surface was a phone number and maybe a chat widget. Today, it’s voice, chat, SMS, social DMs, a mobile app, a self-service bot, and soon a small army of AI agents acting on customers’ behalf. The channel isn’t the vulnerable point anymore; the identity of the person, or the bot, on the other end of that channel is.
That’s not a security abstraction; it’s the exact seam attackers are already working. Credential-based attacks are low-cost and high-reward compared to something like a zero-day exploit, and AI has only made them cheaper and faster to scale. Contact centers have been living this reality for years without always naming it. It’s why account takeover through the “forgot my password” flow, and social-engineering a live agent into resetting an account, remain two of the most reliable fraud paths in existence. The friendliest, most helpful agent on a team is also its softest target, because helpfulness and gullibility share a doorway.
AI Copilots: The Problem and the Opportunity
AI has changed the job of a brand-new security analyst. Instead of years of training before someone can competently query a SIEM, a level-one analyst can now ask, in plain English, for the system to pull logs, cross-reference threat intelligence, and check whether a credential has surfaced in a breach dump, then hand back an enriched answer. The barrier to entry didn’t just lower. It nearly disappeared.
That is precisely the promise behind AI copilots in the contact center, and for once, the hype and the substance line up. A day-one agent with a well-built AI copilot can pull account history, summarize the last several interactions, check entitlements, and suggest a resolution path without months of ramp time. Amplix’s research into AI voice agent platforms points to the same shift: the technology is converging on collapsing the learning curve for junior talent. The org charts stay separate, but the underlying pattern doesn’t.
Friction Is a Design Choice, Not a Security Requirement
Human-centered design in security requires weighing the friction imposed on users against its actual costs, rather than focusing solely on potential deterrence. Excessive security friction carries a significant economic cost, leading users to seek “desire lines” or workarounds wherever authentication processes become over-engineered.
Hold that up against a typical contact center IVR authentication flow: enter a sixteen-digit account number, answer a knowledge-based question about an account closed years ago, then repeat those same details to a live agent. That’s security theater dressed up as verification, and it punishes the legitimate customer far more than it deters a fraudster who has already purchased the answers to those questions on a forum for a few dollars.
The fix in both worlds is the same: minimize friction for the real user, maximize it for the attacker. Passwordless authentication, voice biometrics, device-based trust signals, and behavioral fraud scoring can verify a caller in the background while they’re still saying “hello.” That’s not a nice-to-have CX upgrade; it’s the actual security upgrade, because reducing friction for legitimate users is what makes strong authentication adoptable at all. It’s also the exact terrain Amplix’s customer experience practice works in: conversational AI, self-service design, and conversation intelligence tools built around removing friction without loosening the guardrails.
An HR Function for AI Agents
This is the idea hardest to shake: are businesses approaching a point where AI agents need something like an HR function? Not HR in the literal sense, but the scaffolding associated with employees: a defined role, an owner, an onboarding process, training, access entitlements, a way to handle mistakes, and a way to resolve conflicts when two agents disagree.
That function belongs under AI governance and identity governance, not HR proper, but the instinct is correct. An AI agent is an identity. It needs to be provisioned, entitled, monitored, and, critically, offboarded, the same way a departed employee’s badge and VPN access get disabled. It’s the exact failure mode waiting for any contact center that spins up an AI agent for a pilot project, forgets to formally decommission it, and leaves a live identity with live entitlements sitting in the environment indefinitely.
Contact centers deploying agentic AI to handle billing disputes, process refunds, or update account details need to give that agent an owner, an access scope, an audit trail, and a kill switch: the same governance rigor applied to a human employee with access to customer PII and payment systems. That visibility requirement, tracking what happened in every interaction, human or AI-driven, rather than building governance after the fact, is exactly the gap a recent Amplix look at agentic AI readiness in the contact center flags as the next architecture problem. Most contact centers have a plan for training their AI agents. Very few have a plan for retiring one.
The Real Takeaway on Identity and AI Implementation
The goal isn’t zero friction, and it isn’t zero risk; it’s imposing cost on the attacker while removing cost from the legitimate user. Every dollar and every second an attacker is forced to burn is a dollar and a second a security team gets back to detect and respond. Every ounce of friction stripped from a genuine customer’s authentication experience is CSAT, retention, and handle time recovered.
Contact centers have spent the last decade optimizing the customer journey. The next decade will be about optimizing the identity journey underneath it, for the humans calling in, for the agents helping them, and now for the AI agents doing a growing share of the work in between. Cybersecurity got there first because it had no choice. Contact centers can get there now because the tools finally exist to do it without the trade-off long assumed to be mandatory: that more security has to mean more pain.
How Partnering With Amplix Can Help
When it comes to implementing AI across your contact center, there is, and always will be, risk, including the risk of doing nothing.
Contact Amplix today to see how we can bring the same identity governance discipline that cybersecurity teams have spent a decade refining to your AI agents, your authentication flows, and your customer experience strategy.
Frequently Asked Questions
How can contact centers secure the AI agents that handle customer interactions?
Securing an AI agent starts with treating it like an identity, not a feature. That means giving each agent a defined access scope, an audit trail, monitoring for unusual behavior, and a clear owner accountable for its performance. Input and output controls also matter: contact centers need guardrails on what a customer can prompt an AI agent to do and on what the agent is allowed to say or act on in return.
What is agentic AI security, and why does it matter for contact centers?
Agentic AI security refers to the practices that govern AI systems capable of taking action, not just answering questions, such as processing a refund or updating an account. It matters for contact centers because an agent that can execute transactions carries the same risk profile as an employee with access to billing and PII systems, and needs equivalent oversight.
Why does identity governance matter for AI agents in customer service?
Without identity governance, an AI agent deployed for a pilot project can be left with live entitlements long after the pilot ends, the same way a departed employee’s badge access can linger if IT never revokes it. Identity governance ensures every AI agent is provisioned, monitored, and formally offboarded when it’s no longer needed.
What are the biggest challenges of securing AI agents in the contact center?
The most common challenges are treating AI agents as software features instead of identities, skipping formal offboarding when a pilot ends, and underestimating how quickly credential-based attacks and social engineering can be automated against live agents and AI agents alike.
How do AI agents handle data privacy and security in customer interactions?
Well-governed AI agents operate within a defined access scope, tied to the same compliance and PII-handling requirements as human agents, with monitoring in place to flag when an interaction touches sensitive data outside normal patterns.
How can contact centers reduce authentication friction without increasing fraud risk?
Passwordless authentication, voice biometrics, device-based trust signals, and behavioral fraud scoring can verify a legitimate caller in the background, often before a live agent even picks up. The goal is to make verification invisible to the real customer while making it expensive for an attacker to fake.