My Advice to Banks on AI: Roy Moussa of GetVocal
GetVocal's CEO Roy Moussa shares why banks need deterministic architecture, not just smarter chatbots, to scale AI responsibly across customer interactions.
I spoke with Roy, co-founder and CEO of GetVocal, who has spent over a decade building purpose-led AI companies for regulated industries. Founded in 2023, GetVocal combines deterministic logic with generative AI to help organisations automate customer interactions without sacrificing accountability. Roy shares practical advice on how banks can deploy AI at scale whilst maintaining the control and auditability that regulators demand.
Over to you Roy - my questions are in bold:
Can you give us an introduction to you and an overview of your organisation?
I'm Roy Moussa, the co-founder and CEO of GetVocal. I've spent the past 13 years building purpose-led AI companies and founded GetVocal in 2023 with my long-time partners Antonin Bertin and Sebastião Zaragoza, after seeing the same challenge repeatedly emerge in regulated industries.
We saw that organisations were under pressure to automate customer interactions, but the available tools forced a choice between scale and accountability. Human-only models can no longer keep up, while opaque AI systems made it difficult to understand, govern or explain decisions.
GetVocal's model combines deterministic logic, defined protocols and context graphs with generative AI layered on top. This allows AI to operate within clear boundaries that are aligned to internal policies, workflows and regulatory requirements like the EU AI Act, while also allowing for the nuance and dynamism of natural discussions. Human teams always enjoy full visibility into how decisions are made and the ability to step in when judgement, empathy or escalation is needed, while still benefiting from automation. The aim is to create a system of accountable automation, where it can grow alongside human teams without the enterprise losing oversight or accountability. These capabilities are particularly important in highly-regulated environments like the financial services sector.
If you were advising a bank CEO today, what would you say is the single biggest mistake they're making with data and AI?
The single biggest mistake bank CEOs are making with AI is leaving its potential on the table.
Most executives assume the biggest risk is deploying AI without ownership, auditability or reliability. Fair concern. But that problem is now solved at the architectural level, and the banks still treating it as unsolvable are the ones falling behind.
Here's what I see in the market: most banks confine AI to the first five to 10 percent of the customer experience: FAQs, intent detection, collecting an account number before a human takes over. That caps adoption, caps impact and caps ROI. It also sends a quiet message to your customers that you don't trust your own AI and leaves them frustrated elsewhere.
At the other end, a smaller group pushes generative AI directly into high-stakes territory: transactions, fraud queries, dispute handling. Pure LLM agents bolted onto guardrail stacks. The intent is understandable, but the architecture is wrong. Next-token prediction cannot enforce a compliance rule. At banking scale, even a one in 10,000 hallucination rate is a daily occurrence and no amount of bolted-on controls changes that.
The banks getting this right are choosing a different architecture entirely. They're not rolling the dice by trusting business logic, policies and compliance rules to "prompt and pray." They're building on newer, graph-based technology. AI handles language understanding, generation and non-linear conversation paths while being firmly tethered to the underlying graph, a kind of bedrock layer that cannot be broken. That means every decision is logged, governed and auditable to any regulator.
That's how Vodafone, Deutsche Telekom and Glovo run AI at real enterprise scale. It's the same standard banks should hold themselves to, and the technology to meet it already exists.
So, if I'm advising a bank CEO today, the mistake to avoid isn't moving too fast. It's spending another year convinced the trust problem can't be solved, while a competitor proves it can.
What's one AI or data capability banks should prioritise in the next 12–18 months, and why?
Banks don't need smarter chatbots or a better generative model to win the next 12 to 18 months. They need a deterministic layer, the bedrock which I mentioned before that sits beneath the conversation and governs every decision the AI is allowed to make. That's the capability that unlocks everything else.
Today, most AI agents decide for themselves what happens next in an interaction. That's precisely why trust is so hard to keep at enterprise scale. The fix isn't more prompt engineering or a bigger model. It's separating two jobs that should never have been combined: language generation and business decision-making.
A governed decision layer makes your rules, compliance requirements and risk thresholds explicit. Every interaction follows a path the bank defined. Every step is logged. Every escalation has a traceable trigger. Your regulator gets a complete audit trail, not a model card and a hope.
We call this architecture ContextGraphOS. It grounds every AI agent in a living model of how your bank actually works: your protocols, your procedures, your policies. The AI then acts on what the customer is saying and how they're saying it, sentiment, intent, drop-off signals, within the bounds you've set. Business logic is structure. LLMs handle natural language. Neither can override the other.
The payoff is scale without new risk. If you prioritise one capability in the next 18 months, make it this one. Everything downstream, compliance posture, automation rate, customer trust, depends on getting the decision layer right.
Where do you see banks overestimating AI, and where are they underestimating it?
Banks overestimate what LLMs can do alone and underestimate what their own people bring to the equation.
On the overestimation side: LLMs are excellent at language, not at judgment. Remember, these are models that can write a PhD thesis today – and tomorrow, recommend walking to the car wash if it's close by to wash your car.
Yet, most banks still deploy chatbots that interpret what a customer means, decide what happens next, and pass loosely structured inputs into tightly regulated systems. That's the opposite of how your bank actually operates. Your human agents work against clear protocols, procedures and compliance requirements. Every interaction follows defined standards and risk thresholds. AI should be held to that same bar, not a lower one.
On the underestimation side: human judgment is still the most valuable input in the system. People set the protocols. People handle the exceptions. People stay accountable for outcomes. The question isn't whether to keep humans in the loop, it's whether you give them a system designed to make their judgment compound and accelerate automation.
That's what a proper control layer does. At GetVocal we call ours the Agent Control Tower. When the AI hits an edge case, it consults a human operator the way a junior agent would escalate to a supervisor. The human resolves it. The AI shadows the resolution, captures the structured knowledge and performs better next time. We call that compounding loop the Human-AI Flywheel. Quality and automation rates rise together, not at each other's expense. Sometimes the AI Agent will just ask for a quick confirmation from the bank employee, then continue helping the customer. This turns what would otherwise be several minutes of handling time after a handover into a mere 20 seconds of quick human input.
The balance is simple. AI brings consistency and scale. People bring judgment and accountability. The banks that win will be the ones that stop framing this as either/or.
What does "good" actually look like when AI and data are working well inside a bank?
AI that works well inside a bank is invisible to the customer and completely transparent to the business.
To the customer, it feels like any other interaction with your bank, maybe even easier! Natural. Resolved in one conversation. No "please hold while I transfer you" theatre. The AI handles the full interaction from start to finish, not just the first 30 seconds.
For the bank, it's the opposite of invisible. Every decision the AI makes is logged, governed and explainable. Your compliance team sees exactly which rule fired, which policy applied and which path the conversation took. Your service leaders have full visibility into outcomes and can stand behind them when a customer escalates, without having to step in pre-emptively. Your regulator gets a complete audit trail on request.
Compliance isn't a review stage. It's the architecture. Protocols, permissions and escalation paths are grounded in our ContextGraphOS from day one, so the AI simply cannot operate outside them. Speed and control stop being a trade-off.
Nicomatic runs this model for industrial knowledge management and sees zero percent hallucination or data leakage risk. And let me repeat that because it's worth thinking through how different that is from the rest of the market: a zero percent hallucination rate. That's what good looks like in practice: regulated outcomes, measurable impact, zero drama.
The test is simple. If your CX leader, your compliance officer and your CFO all look at the same AI deployment and each see what they need to see, you've got it right.
What's the hardest AI or data decision bank executives are avoiding right now, and why?
The hardest decision is committing to AI at full scale, not just in a contained pilot.
That requires a shift from short term experimentation to building something that can actually hold up day to day. Many banks delay this because it feels safer to keep AI agents contained, but small pilots do not reflect what happens when these systems are used across the business.
In banking, control matters more than creativity, which is why technologies like IVR – automated telephony systems that route callers – have proved durable. However, the human and phone-first era of customer service has reached the end of its life. Bank CEOs must now reconcile two truths: that AI adoption is inevitable and that they no longer need to trade performance for control. Technology wise, every AI decision can be grounded and auditable. The architecture is already there.
The human-AI workforce will be the default operating model for most enterprise banking in the next few years. The hard decision for bank CEOs right is how soon they embrace this change and build solid foundations for safe and scalable conversational AI adoption.
Thank you Roy! You can connect with Roy on his LinkedIn Profile and find out more about the company at getvocal.ai.