AI Agents

AI Integration Services: What They Cost and How They Work

October 1, 2026 18 min read yatin
ai integration services

AI integration services connect a model — a language model, an agent or a document-AI pipeline — to the systems your business already runs, so it can read the right data, act inside existing workflows and leave an audit trail. Most of the work is connectors, permissions and failure handling, not the model — which is where AI pilots usually stall.

The scale of the problem is easy to underestimate. MuleSoft’s 2026 Connectivity Benchmark found that the average organisation now runs 957 applications and only 27% of them are connected to each other; 82% of IT leaders named data integration as one of the biggest challenges in using AI. The survey did not include India, but anyone who has tried to connect Tally to anything will recognise the pattern. Gartner, meanwhile, found that at least 50% of generative AI projects had been abandoned after proof of concept by the end of 2025, citing poor data quality, weak risk controls, rising costs and unclear business value.

This guide explains how AI is actually connected to enterprise systems, walks through one integration end to end, sets out what it costs in India, and covers the part buyers most often forget to ask about: what happens when it breaks.

The four ways AI gets connected to an existing system

Every integration uses one of four patterns, or a combination. Pick the highest one on this list that the system supports: each step down is cheaper to start and more expensive to keep running.

Integration patterns compared

Pattern When it fits Indicative build effort Running cost What breaks it
1. API-level (REST, OData, Microsoft Graph) The system has a documented, supported API and the workflow needs answers in seconds 1–3 engineer-weeks per system Low Rate limits, expiring credentials, and API versions being retired
2. Event- or queue-driven (webhooks, a message broker) High volumes, several consumers of the same event, work that can happen a few seconds later 3–6 engineer-weeks for the backbone, then less per workflow Medium — the broker has to be run Messages arriving twice or out of order, and messages that fail every retry
3. Database-level or change-data capture No usable API, but you can read a replica of the database 2–5 engineer-weeks Medium Schema changes, replica lag, and vendor support terms that forbid direct reads
4. User-interface automation (RPA) No API and no database access — the last resort 1–3 engineer-weeks High — it breaks when a screen changes Any change to the screens it clicks through

API-level integration is the default where it exists, and it exists more often than it used to. SAP publishes released APIs for S/4HANA — OData and SOAP services whose stability SAP guarantees from release to release. Microsoft 365 is reached through Microsoft Graph. Even TallyPrime exposes its data as XML over HTTP and, from version 7.0, as JSON.

Event-driven integration earns its cost when the same business event — an invoice received, a loan disbursed, a claim filed — needs to reach several systems, or when volumes spike. Database-level integration is the honest answer for in-house applications with no API, provided the vendor’s support contract allows it. User-interface automation should be a bridge, not a foundation: it works until someone moves a button.

A worked example: supplier invoices from inbox to Tally

Here is how one common integration runs end to end. It is a typical pattern, not a specific client’s system, and it shows where the effort goes. The job: supplier invoices arrive as PDF attachments in a shared mailbox; they need to be read, checked and posted as purchase vouchers in TallyPrime, with anything doubtful sent to a person.

The integration, step by step

Step What happens How it connects What happens when it fails
1. Trigger A new email with a PDF arrives in the accounts-payable mailbox Microsoft Graph change notification on the mailbox Missed notifications are caught by a scheduled sweep every 15 minutes
2. Extract Document AI reads supplier name, GSTIN, invoice number and date, line items and tax Model call on a private endpoint; the PDF never goes to a public service Low-confidence fields are flagged, not guessed
3. Validate Supplier matched to the vendor master, GSTIN format checked, totals reconciled, invoice number checked for duplicates Read from Tally’s masters; duplicate check against posted vouchers Any mismatch sends the invoice to the review queue
4. Decide Above the confidence threshold it posts automatically; below it goes to a person with the doubtful fields highlighted Review queue in the finance team’s existing tool The threshold starts high and comes down as measured accuracy improves
5. Post Purchase voucher created in TallyPrime XML over HTTP or JSON (TallyPrime 7.0 and later) Invoice number used as the key, so a retry cannot post twice
6. Record Source email, model version, extracted values, reviewer and voucher number logged together Append-only log Every voucher can be traced back to the email it came from

Notice how little of this is the model. Step 2 is one call. Steps 3 to 6 are what make it safe to switch on: the checks against master data, the duplicate protection, the human queue and the audit trail. That is also where the build effort goes.

In the first week after go-live, everything still goes to the review queue, and the team compares what the system would have posted with what the reviewer approved. As measured accuracy rises, the automatic-posting threshold comes down, one supplier group at a time. Within about six weeks, routine invoices post on their own and people see only the exceptions. Skipping that ramp is how integrations end up posting forty wrong vouchers overnight.

How long it takes: a realistic timeline for one workflow

The build is rarely the long part. Access, test environments and the evaluation are. A single workflow like the invoice example typically runs like this:

A realistic timeline for one AI workflow

Weeks What happens What you should be able to see
Before week 1 Access requests and the security review start — service accounts, test environments, data-sharing approval Named approvers and dates, not a promise to ‘sort access out’
1–2 Connectors built against a test environment; a sample of real documents collected and labelled to form the evaluation set The first end-to-end run on test data, and the evaluation set agreed with the business
3–4 Validation rules, the review queue and the audit log built; the system runs in shadow mode — it proposes, people decide A daily comparison of what the system would have done with what people actually did
5–6 Go-live for the first group of suppliers, with automatic posting only above a high confidence threshold and a daily reconciliation report Measured accuracy on live traffic, and the first exceptions handled through the queue
7–10 Coverage widened, thresholds lowered where the numbers support it, the runbook handed over Share of items handled without a person, and time saved per week

The three things that most often add weeks are access approvals that start late, test environments that do not behave like production, and master data that turns out to be incomplete — suppliers missing from the vendor master, GSTINs that were never captured. Start the first on day one, test against production-like data as early as the security team allows, and treat the third as a finding, not a failure: the integration has just shown you a data problem that was already costing money.

Workflows first, agents second

A workflow has fixed steps with AI in one or two of them, like the invoice example. An agent decides its own steps and chooses which tools to call. Agents are the more exciting idea and the riskier purchase. Gartner predicts that over 40% of agentic AI projects will be cancelled by the end of 2027 because of escalating costs, unclear business value or inadequate risk controls, and estimates that only about 130 of the thousands of vendors selling agentic AI are the real thing.

Agents also make integration more important, not less. Every tool an agent can call is an integration, with its own credentials, permissions and failure modes, and 86% of IT leaders in the MuleSoft survey said that without proper integration, AI agents can introduce more complexity rather than less. The practical sequence is to build the workflow first, with its connectors, validation and audit trail. Then let an agent use those same connectors — read-only at first — and route every write it proposes through the same validation and review path the workflow already has. The agent gets the flexibility; the business keeps the controls.

The systems that make it hard

Four kinds of system account for most of the difficulty in Indian enterprises.

SAP. Build against SAP’s released APIs or through SAP Integration Suite, SAP’s integration platform, rather than reading ECC tables directly. SAP’s mainstream maintenance for Business Suite 7 ends in 2027, with extended maintenance to the end of 2030; an integration built on tables that disappear in the migration will be rebuilt.

Microsoft 365. Graph gives access to mail, files and SharePoint, and it can be scoped to specific sites with selected permissions rather than the whole tenant. Scope it. AI assistants in Microsoft 365 surface whatever the user is already permitted to see, which turns years of oversharing into something anyone can find by asking. Varonis, whose research covered 1,000 real IT environments, reports that 99% of organisations have sensitive data exposed in a way AI can easily surface. Microsoft’s own SharePoint Advanced Management includes reports built to find overshared sites; run them before, not after.

Tally. The integration methods are straightforward — XML, JSON or ODBC — but Tally usually runs on desktops, often one company file per entity and one installation per branch. The work is in the inventory: finding every instance, agreeing when each is switched on, and handling the one that is always offline.

Core systems with batch windows. Core banking, loan management and older ERPs often accept changes only at set times. An AI workflow that needs to write back must queue its writes for the window and report what happened — which is pattern 2 from the table above, whether or not anyone calls it that. Gartner found that 56% of chief supply chain officers call integrating AI with legacy systems and processes a major challenge.

Documents first: intelligent document processing as an integration problem

A large share of enterprise AI in India starts with documents: invoices with GST details, KYC packs at NBFCs, digital lenders and insurers, claims, purchase orders, delivery challans. The category has a name — intelligent document processing — and it is already mainstream. In AIIM and Deep Analysis’s 2025 survey of more than 600 enterprises, 78% said they are operational with AI in document processing, and two-thirds of new projects are replacing an existing system.

The same research lists integration challenges as the second-biggest constraint on those projects, and that matches what the worked example shows. Reading a document well is now the easy part: current models extract fields from a clean invoice reliably. The hard parts are routing the document to the right workflow, validating what was read against master data, handling the exceptions without losing them, and writing the result back to a system that was not designed to receive it.

So evaluate document AI the way you would evaluate an integration. Ask to see the review queue, the validation rules, the duplicate protection and the audit log, not just the extraction accuracy on a demo set. A vendor who leads with a percentage and cannot show you the exception path has built half the product.

What AI integration costs in India

Indian firms that build AI systems bill in a published band. Clutch’s AI development pricing guide, updated in September 2026, lists India at $25–49 an hour, and reports an average project cost of about $120,600 over a typical timeline of ten months. Budgets are still modest by that measure: in the EY-CII AIdea of India outlook, more than 95% of Indian organisations said they allocate less than 20% of their IT budget to AI, even though 47% already have several generative AI use cases live.

Indicative cost by integration scope, at $25–49 an hour

Scope Example Indicative effort Indicative build cost What it costs to run
One workflow, one system with an API Invoices from a mailbox into Tally 3–6 engineer-weeks $3,000–11,800 (about ₹2.6–10.3 lakh) Monitoring, threshold tuning, model updates
One workflow across two or three systems, with approvals Purchase-order matching across SAP, email and an approval tool 10–20 engineer-weeks $10,000–39,200 (about ₹8.8–34.5 lakh) The above, plus maintaining each connector
A shared integration layer serving several AI use cases Event backbone, identity, logging and evaluation used by every workflow 30–60 engineer-weeks $30,000–117,600 (about ₹26 lakh–₹1.03 crore) A small platform team, in-house or managed

The shared layer is the line that decides whether the second and third use cases are cheaper than the first. Organisations that build each AI workflow with its own connectors, its own logging and its own security review pay the full price every time. Those that build the layer once pay a little more up front and much less afterwards.

When it breaks: rollback, replay and the audit trail

The question an enterprise buyer should ask every vendor is this: if the system posts forty wrong entries overnight, how do we find them and reverse them before the books close? The answer should cover six things.

None of this is exotic. It is standard integration engineering, and it is usually missing from AI pilots because the pilot never had to survive a bad night. Ask to see it working before anything is allowed to write to a system of record.

Security, access and what your legal team will ask

Four questions come up in every security review of an AI integration, and it is faster to answer them in the design than in the review.

What can the service account reach? Scope every credential to the minimum: specific SharePoint sites rather than the tenant, specific SAP services rather than a dialogue user with broad roles, read-only wherever writing is not required. Keep credentials in a secrets manager, not in configuration files.

Where does the data go? If documents contain personal data, the DPDP Act applies to the model call as much as to the database. Know where the model runs, what the provider’s terms say about retention and training, and whether an in-country or on-premise model is the better fit for that workflow.

What is logged, and for how long? The audit trail that makes rollback possible also holds personal data. Decide the retention period and who can read it before go-live.

Can a document instruct the model? An invoice or an email can contain text written to manipulate an AI system. Treat document content as data, never as instructions; restrict what actions the model can trigger; and require validation before any write. Our secure retrieval systems are built on these rules.

Who owns it after go-live

Integrations do not stay finished. Source systems are upgraded, APIs are retired, new document formats arrive and thresholds need retuning. MuleSoft found that IT teams already spend 36% of their time building new custom integrations; AI workflows add to that load unless someone owns them.

Ownership means a named person or team, a runbook for the common failures, monitoring that reaches that person, a service level for fixing breakages, and a change process for when an upstream system changes. The payoff is longevity: Gartner found that 45% of organisations with high AI maturity keep their AI initiatives in production for three years or more, against 20% of those with low maturity.

This is how we work. Every integration starts from the systems you already run, and the data work underneath it is scoped the same way as in our guide to data engineering consulting. We prove the workflow on your own documents in a 4-week AI proof of concept, build the connectors, the review queue and the audit trail as one piece, and stay on to run it if you want us to. Built fully custom, or accelerated by our own LLM and inference stack where it speeds delivery — the choice is yours. It is the core of our enterprise AI solutions and of the custom AI solutions we build.

Frequently asked questions

What are AI integration services?

AI integration services connect AI models, agents or document-AI pipelines to the systems a business already uses — ERP, CRM, email, document stores and accounting software — so the AI can read the right data, act inside existing workflows and keep an audit trail. The work covers connectors, permissions, validation, error handling and monitoring.

How does AI integration work?

An event in one system, such as a new email or a new order, triggers a workflow. The AI reads or decides something, the result is validated against business rules and master data, and it is either written back to the target system or sent to a person for review. Every step is logged.

How much does AI integration cost in India?

Indicatively ₹2.6–10.3 lakh for one workflow and one system with an API, ₹8.8–34.5 lakh for a workflow across two or three systems with approvals, and ₹26 lakh to about ₹1 crore for a shared integration layer, based on India billing rates of $25–49 an hour. Running costs are extra.

How long does AI integration take?

A single workflow connected to one system with a documented API takes three to six engineer-weeks. A workflow across several systems with approvals takes ten to twenty. A shared integration layer takes several months. Access approvals and security reviews are the most common causes of delay.

How do you integrate AI into legacy systems?

Use the highest-level interface the system supports: an API if one exists, a message queue if the system can publish events, a read replica with change-data capture if it cannot, and screen automation only as a last resort. Respect batch windows, and queue writes rather than forcing them.

How do you integrate AI with SAP or Tally?

For SAP, use SAP’s released OData or SOAP APIs or SAP Integration Suite rather than reading tables directly. For TallyPrime, use its XML-over-HTTP interface, native JSON from version 7.0, or ODBC for reporting. In both cases, validate against master data before writing anything back.

Is AI integration secure?

It can be, if credentials are scoped to the minimum, personal data is handled under the DPDP Act, logs are retained and protected deliberately, document content is never treated as instructions, and every write is validated. Ask any vendor to show the rollback and audit trail before go-live.

Y

yatin

Enterprise AI team at AIVeda.

← Previous

Multi-Agent Systems in the Enterprise: Beyond a Single Private LLM

Next →

AI Strategy Consulting: How to Build a Roadmap That Pays