AI isn't simply going to automate KPO work. It changes what that work leaves behind. Once a workflow runs on AI, it starts producing machine-readable know-how: prompts, exception libraries, evaluation sets, retrieval indexes, decision logic. That's bad news for the labour-arbitrage model, and it makes handing the intelligence layer to someone else a far more expensive decision than it used to be. Where I think this lands is a split. Commodity work stays outsourced and gets more software-like. The proprietary stuff, the workflows and the institutional knowledge, drifts back toward capability centres that firms own.
Outsourcing is getting squeezed from both sides
For about twenty years, knowledge-process outsourcing ran on a fairly simple idea. If work was complex but repeatable, you could break it into pieces and ship it from expensive labour markets to cheaper ones. In financial services, that meant company research, financial spreading, database upkeep, credit analysis, presentation production, monitoring and first-pass drafting. You sold analyst-hours. Your moat was the wage gap.
That model is under real pressure now, and honestly the reason isn't subtle. AI can do, or seriously speed up, a growing share of those tasks. The benchmarks keep climbing: OSWorld went from roughly 12% to 66.3% in 2025, and leading systems now hit somewhere around 60–90% on selected professional evaluations. I'm not claiming AI can replace a financial analyst end-to-end. It can't, at least not yet. What it can do is shrink the human time it takes to produce a piece of routine knowledge work, and it's doing that quickly.
Still, productivity is the easy part of this story. What I think most people are missing is ownership. AI doesn't just use information. It turns workflows into assets you can reuse, and that moves the line between what a company can safely hand off and what it really ought to keep.
1. AI breaks the old KPO equation, swapping analyst-hours for software and expert review
The old KPO maths was easy to follow. A bank swapped expensive onshore staff for cheaper offshore staff, and the vendor pocketed part of the difference. AI changes who you're comparing. It used to be a London analyst against a Bangalore analyst. Increasingly, it's a Bangalore analyst against an AI-enabled workflow with a few experienced people watching over it.
Think about a sector-research pack. A junior analyst used to find the companies, dig through filings, pull financials, extract data, compare peers, summarise what was happening in the industry, fill spreadsheets, build charts, draft commentary and format the lot before anyone senior looked at it. A lot of that now collapses into retrieval, extraction, drafting and tool use. The person's job moves up. They frame the question, pick the method, sort out the ambiguous bits, check sources, use their judgement and sign off.
What clients pay for is shifting from hours to verified output
| Model | Primary production unit | Client buys |
|---|---|---|
| KPO 1.0 | Junior analyst-hours | Capacity at lower cost |
| KPO 2.0 | AI-augmented analyst-hours | Higher productivity |
| KPO 3.0 | AI workflow + expert oversight | Outcome / knowledge infrastructure |
Why does this matter? Professional-services firms are built like pyramids, with a wide base of junior people. That base is exactly what AI is good at replacing: retrieval, document extraction, basic spreading, transcript analysis, benchmarking, summaries, presentation drafts, routine monitoring. So I'd bet the first thing to go isn't the industry. It's the shape of it.
You can already see this in banking. One North American bank used a multi-agent system to cut the time spent preparing credit-risk material. Credit decisions got about 30% faster, and relationship-manager productivity more than doubled. Nobody had to get rid of the credit analyst for this to hurt outsourcing. Strip out enough junior hours and the spread the whole model relies on starts to shrink.
2. The bigger shift: outsourced work is turning into a proprietary asset
This is the part I find more interesting than automation itself. In the old setup, outsourced work took in data and sent back a spreadsheet, a report, a model or a presentation. That was it. With AI in the loop, the work leaves something else behind as well: prompts, taxonomies, evaluation sets, exception libraries, retrieval indexes, workflow configurations, agent instructions, fine-tuning data and decision logic that has finally been written down.
You can't automate a process until you understand how it actually works, and that knowledge almost never lives in the policy manual. It lives in the exceptions. Why does this customer get escalated? Why was that credit turned down when it ticked every box? How do you adjust EBITDA in this odd case? Which management claims do experienced bankers quietly ignore? What does the operations team do when a case falls between two rules?
Most of that used to stay in people's heads, inside the organisation. AI drags it out into the open, in a form a machine can read. So whoever builds the workflow walks away with something worth more than the data: a working picture of how your business really runs.
And as the models themselves become commodities, that context is where the value ends up. Everyone is buying from the same handful of suppliers. What sets you apart is your own data, your history, your rules, how you handle exceptions and the decisions you've piled up over the years. Outsource the AI layer, and you may be outsourcing a piece of your firm's memory along with it.
3. AI makes the data chain longer, and leaks easier to cause and harder to spot
Outsourcing has always had a control problem, because confidential information leaves the building. AI adds more stops on the way. A vendor might run its own orchestration layer, a third-party foundation model, a vector database, monitoring tools, external APIs and a few subcontractors. Prompts and outputs get logged. Documents get turned into embeddings. Feedback gets kept. Agents need access to email, CRM, file repositories, ERP systems, market-data platforms and internal databases.
The data path used to be Bank → KPO → Bank. Now it looks more like Bank → KPO → orchestration layer → model provider → supporting infrastructure → KPO → Bank. Each step brings its own contract, retention policy and access rules, and each one is another place where something can go wrong.
There's a contract gap here too, and I doubt most firms have closed it. Standard agreements talk about who owns and deletes “customer data”. But AI creates things that don't sit neatly in that definition: prompts, embeddings, synthetic examples, evaluation data, model configurations, workflow logic and whatever gets inferred from the customer’s data. So the question changes. It used to be “Who owns my data?” Now it's “Who owns what was learned from it?”
A simple investment-bank example
Say a bank is advising on an acquisition that hasn't been announced. A KPO analyst gets a draft information memorandum and is asked to update the comparable-company analysis and put together some pitchbook pages. The deadline is tight, so the analyst pastes part of the document into a personal generative-AI account to summarise the target, find peers and rough out some commentary.
Nobody is being malicious. The analyst just wants to get it done. But confidential deal information has now left the bank’s controlled environment, and maybe the KPO’s as well. The bank probably has no contract with that AI provider, no idea what the retention settings are and no record that anything happened. If the account gets compromised, months of client work could be sitting in the chat history. And if the vendor works for rival banks, sloppy separation of retrieval systems, prompts or shared knowledge bases gives the information one more way to spread.
That's a different kind of risk from what we're used to. A leak used to mean someone copied a file. Now it can mean the document plus all the thinking wrapped around it: the prompts, the summaries, which comparables were picked and why the valuation assumptions look the way they do. You don't just lose information. You lose a piece of how you think.
We've already had warnings. Employees have pasted sensitive source code and internal information into public AI tools. Several big banks clamped down on staff use early on. Third parties are still a major source of breaches, and outsourced workers have been targeted with social engineering and bribes. What AI adds is a route that doesn't need a hacker or a criminal at all. It just needs someone in a hurry.
4. The boundary splits: outsource the commodity work, keep the intelligence
I don't think any of this kills outsourcing. It splits it.
Routine, standardised work can stay outside the firm, and it may get even more attractive to outsource as providers automate it. A lot of it will start to look less like labour outsourcing and more like services-as-software. The client pays for an outcome, and the provider works out how much human effort, software and AI infrastructure it needs to deliver it.
Work that generates proprietary data, encodes the way you make decisions or captures what your firm knows is a different story. There, the argument for keeping the intelligence in-house gets a lot stronger. You can still put that team in India, Poland, the Philippines or anywhere else that's cheaper. I just expect more firms to do it through a captive Global Capability Centre than through an outside KPO.
That way you keep most of the cost advantage of the location, and the prompts, workflows, datasets, evaluation systems and decision logic stay inside your own security and governance perimeter. Put simply, AI makes where the work happens matter less, and who owns it matter more.
5. The new competition is funded software, and legal shows where it's heading
There's another squeeze coming, and I don't think the outsourcing industry is taking it seriously enough. It isn't coming from rival vendors. It's coming from software companies with a lot of venture money behind them. Rogo, which builds AI agents for bankers and investors, raised a $75 million Series C in January and then a $160 million Series D in April, reportedly at around a $2 billion valuation. Read its pitch and it's basically the junior-analyst job description: Excel models, memos and slide decks, wired into a firm's CRM, SharePoint and data providers like Capital IQ and FactSet.
Then there's the plumbing, which gets less attention but may matter more. MCP, the Model Context Protocol, lets a model connect directly to market data, document stores and internal systems. Once a model can pull the filings, read the data room and write into the spreadsheet on its own, a lot of what KPO teams were paid for, the fetching, the copying, the reformatting, stops being a job. It becomes a connector someone sets up once.
Legal is a bit further down this road, and it's a useful preview. Harvey raised $550 million at a $15.5 billion valuation in September, and says more than 200,000 lawyers now use it. Its annualised revenue reportedly went from about $190 million in January to more than $350 million by August. Plenty of that is work legal process outsourcing (LPO) firms used to count on: first-pass document review, due diligence across data rooms, contract extraction, early drafts. That was the bread and butter shipped to teams in India and the Philippines. We're already seeing Harvey take a bite out of it, and I doubt it stops at the low end.
The part that should really worry LPO and KPO providers is where the work goes next. When a law firm or a bank buys Harvey or Rogo, the work doesn't move to a cheaper vendor. It comes back inside, done by the firm's own people on the firm's own tools. It's the return of control again, just arriving faster than I expected. The providers that come through this will be the ones building on top of these platforms, or building something better, rather than trying to beat them on price per hour.
KPO won't die, but its growth will come apart from headcount
This clears up something that looks like a contradiction. Forecasts can keep showing the KPO market growing even while AI squeezes jobs and margins. Companies may want more knowledge work than ever, while each unit of it takes far fewer people to produce. More research, more compliance, more monitoring and analysis, with smaller teams doing it.
The firms that should worry are the ones still selling human hours. The ones that do well will climb the stack and sell proprietary data, domain expertise, AI infrastructure, workflow integration, judgement and accountability. Their revenue can keep rising even after the old link between revenue and headcount snaps.
Geography shifts as well. Offshoring made sense because the wage gaps were huge. Once labour is a smaller slice of the cost, the question stops being “Who has cheaper analysts?” and becomes “Who has the best data, workflows, models, domain expertise, client integration and trust?”
6. Value is migrating, and margins will follow it
If I had to squeeze the whole argument into one line, it would be this: value is moving away from the people doing the work and toward whoever owns the workflow, the data and the decision logic around it. In the old model, the gap between onshore and offshore wages was the profit pool, and the KPO took a healthy slice of it. As AI eats the junior hours, that pool shrinks. Some of it goes back to the client as lower prices. Some goes to the software layer, the Rogos and Harveys and the model providers underneath them. What's left for a provider still billing by the hour gets thinner every year.
So what happens to margins? For the hour-sellers, I think it's a slow squeeze rather than a cliff. Clients will start asking why they're paying for a team of forty when the tools suggest fifteen would do, and prices will drift down faster than costs. For providers that make the jump to outcome-based pricing, it can actually go the other way. Sell a finished credit memo or a reviewed data room for a fixed fee, let AI cut your cost to deliver it, and you keep the difference. Same work, very different economics. The catch is that you need the tools, the data and the client's trust to price like that, and most traditional KPOs and LPOs don't have all three yet.
This is also why the case for GCCs keeps getting stronger. A captive centre gives you the cost advantage of the location without handing over the intelligence layer. Your prompts, evaluation sets, exception libraries and agents stay inside your own walls, and every improvement compounds for you instead of for a vendor who also works for your competitors. Five years ago a GCC was mostly a cost play. Today I'd call it a control play.
For the outsourcers, the business model has to change, and I mean the model, not just the tooling. Selling capacity won't cut it. The ones that make it will look more like managed platforms. They bring the domain expertise, the AI infrastructure and the people to supervise it, and they let the client own the data, the workflows and whatever gets learned along the way. That's a painful shift for firms whose entire P&L is built on headcount. I suspect clients will force it anyway, and start writing it into their contracts.
AI security becomes the new control layer
There's one more piece, and it's the one I'd put at the top of any board agenda. Once agents are doing real work, security stops being only about who can see a file. It becomes about what an agent is allowed to do: which systems it can reach, what it can change, who checks its output and whether there's a record of every step it took. An agent with access to email, a data room and a CRM can do in seconds what a careless employee might take a week to do.
And this isn't only a banking problem. KPOs and LPOs running agentic work for clients will need to manage it the way banks manage traders: tight permissions, hard separation between clients, logging and audit trails, human sign-off on anything material, and a quick way to shut an agent down when it misbehaves. Prompt injection, data bleeding between client workspaces and agents quietly overstepping their access are the new versions of old risks. Clients will want proof these controls exist before they hand anything over, and the providers who can show it will win the work. Honestly, this might be where the next real moat sits for outsourcers. Cheap labour got them here. Being trusted to control the machines doing the work is what keeps them in the game.
The real disruption is the return of control
For twenty years, outsourcing showed that complex knowledge work could be broken down, standardised and moved across borders. The irony is that this success is exactly what makes so much of that work easy to automate.
The first-order effect is the one everyone expects: fewer analyst-hours, flatter pyramids, thinner arbitrage margins. The second-order effect is the one I'd watch. With AI, doing the work and creating reusable knowledge become the same thing. Execution and IP creation start to blur together.
That changes the make-or-buy question. The first outsourcing wave asked where the work could be done most cheaply. This one asks something else: where should the knowledge you build by doing the work actually live?
My answer is a market that splits in two. Commodity processes get more automated and stay with outside providers. Proprietary workflows, context and decision systems move toward capability centres the firm owns. Outsourcing isn't ending. Control is just back on the table as a strategic choice.
What worries me is what I'm not seeing. Industry bodies haven't stepped up with rules, regulations or best practices on how AI should be used in this industry, and it's an industry that's clearly ripe for disruption. We need some common ground rules on data ownership, model use, derivative assets and agent security, and we need them before the next leak, not after it.