Profile the CPU usage to see where CPU cycles are spent.
In addition check the packet size of data traffic. If apps are using full 1500 byte frames, then IPsec will have to fragment them (due to own overhead) which means double frame rate and PPS is a constraint as well. Either reduce packet size (which might be impossible) or increase MTU on ethernet interfaces linking both hAP ac2s …
as you can read in first post, the packets are small (618B in fact). Profile of CPU usage shows networking.
I have tested almost every single RouterBoard and no one of them is able to crypt even the quarter of the results that Mikrotik announced. According to RFC2544 the results are showing bidirectional speeds o_O !!!