Locations

Self-hosted AI voice agents for regulated US industries

In a hosted voice pipeline every component that touches the audio is another party your compliance team has to paper. Self-hosting collapses that chain to nothing.

Part of on-premise AI voice agent license

The basics

The argument for self-hosting is architectural, not marketing

A hosted voice pipeline routes your audio through several components, and under US health rules each one that touches protected information is another party to paper. That is the real reason regulated American organisations end up self-hosting, and it is worth stating in those terms rather than in the usual language about security posture. Health information rules extend down the chain: a business associate that subcontracts a function involving protected health information needs its own agreement with that subcontractor, establishing a documented chain of custody back to the covered entity. Financial institutions carry an analogous duty to select, contract with and periodically assess their service providers. Running the platform inside your own environment does not improve your posture against that requirement so much as remove the thing being assessed.

In short

  • The whole stack inside your own cloud account or data centre
  • No downstream subcontractor chain to identify, contract and reassess
  • Access to record systems that were never going to face the internet
  • Retention and deletion on your schedule, enforced by you
  • A deployment that does not need re-reviewing when a state statute shifts

The market

Why these projects stall, and what actually unblocks them

The pattern in regulated American organisations is remarkably consistent. A department identifies a genuine problem — an appointment line that overwhelms staff, a member services queue nobody can hire their way out of — runs a successful pilot, and then hits a vendor risk review. The review is not hostile; it simply asks who else touches the audio. The answer usually involves several components and a couple of names nobody in the room recognises, and from that point the project is not rejected so much as it stops. A year later somebody proposes it again and the same thing happens.

What unblocks it is changing the answer rather than improving the paperwork. When the platform runs on infrastructure the organisation has already assessed, the review stops being about third parties and becomes a set of internal questions with internal answers: which environment, whose credentials, what retention, what monitoring. Compliance teams are generally good at those questions. What they cannot do quickly is take on responsibility for a chain of external processors they did not choose and cannot audit, which is what a hosted deployment asks them to do.

Downstream

How far health-information agreements reach

Where a business associate subcontracts a function involving protected information, a further agreement is required with that subcontractor to establish a chain of custody.

Oversee

What financial institutions owe on providers

The Safeguards Rule requires selecting and retaining only capable service providers, contracting with them to maintain safeguards, and periodically assessing them.

Jan 2027

How far one state AI act has now moved

Colorado's 2024 act was repealed and re-enacted in May 2026 with the effective date pushed to January 2027, and enforcement paused pending rulemaking.

What the rules require

The three things that decide a regulated US deployment

One is about health information, one about financial customer information, and one about the fact that this area of law will not sit still.

HIPAA business associate obligations

The chain, and why removing it is worth more than documenting it

Under the health information rules, a business associate that subcontracts a function involving protected health information must have its own agreement with that subcontractor before disclosing the information, and those downstream subcontractors are themselves business associates bound by the terms of their agreements — a documented chain of custody running back to the covered entity. A cloud provider that stores protected information in that chain is a business associate too. In a hosted voice pipeline, the components handling audio, transcription and generation each sit somewhere on that chain. A self-hosted deployment does not shorten it; it removes it, because there is no external party in the path at all.

FTC Safeguards Rule

The oversight duty a financial institution cannot delegate

Financial institutions covered by the Safeguards Rule must oversee their service providers: selecting and retaining only providers capable of maintaining appropriate safeguards, contracting with them to implement and maintain those safeguards, and periodically assessing them. The obligation stays with the institution regardless of what a vendor promises, which is what makes each additional processor in a call path a recurring cost rather than a one-off approval. Removing the processors removes the recurring assessment along with them, which is usually a larger saving over a few years than the licence difference.

State AI legislation, and its instability

Why a deployment that is not vendor-dependent ages better

State AI law is moving faster than most vendor documentation. Colorado's 2024 act was repealed and re-enacted by legislation signed in May 2026, with the effective date pushed to January 2027 from an already-extended June 2026 date, and the Attorney General has indicated no intention to enforce it or its replacement until rulemaking concludes. Other states have narrowed or widened obligations on similar timescales. An organisation that controls its own deployment can adjust disclosure and handling directly when a rule lands, rather than waiting for a vendor's roadmap to catch up with a statute that has already taken effect.

Recording consent across state lines

A configuration question that self-hosting does not change

Worth stating plainly so it is not lost: self-hosting does not alter the recording rules. States disagree about whether one party or all parties must consent, and a national organisation therefore reads a notice on every call regardless of where the software runs. What self-hosting does change is what happens to the recording afterwards — retention, access and deletion all become internal controls under your existing programme rather than settings you configure in someone else's product and then verify by asking them.

Written from published regulator guidance and the analyses linked below, and not legal advice. The point of this page is to help you frame the internal review accurately, not to tell you what your own compliance function should conclude.

Numbering

Telephony into an environment you control

Self-hosting changes where the software runs. The telephone network still has to reach it, and that part looks familiar.

Numbers terminating in your environment

Provisioned or ported so the call path ends inside your boundary rather than in a vendor's platform that then forwards it onward.

Behind your existing phone system

The agent sits behind the numbers and trunks you already operate, which is usually what makes the change manageable for a telecom team.

Registered caller ID on outbound

Reminder and notification calls dial from numbers belonging to the deployment, which protects answer rates on exactly the calls patients and members most need to receive.

Audio that never crosses the boundary

Recording, transcription and summarisation all execute inside your environment, which is the property that makes the review straightforward.

Area codes we provision in:212 / 646312 / 773617 / 857404 / 470214 / 469704 / 980215 / 267612 / 763615 / 629303 / 720206 / 425216314410 / 443513919 / 984Explore more in the app

Coverage

Where US self-hosted deployments run

The markets our regulated US conversations come from. As with the Canadian equivalent, the location that matters here is your infrastructure rather than any city named below.

  • New York
  • Chicago
  • Boston
  • Atlanta
  • Dallas
  • Charlotte
  • Philadelphia
  • Minneapolis
  • Nashville
  • Denver
  • Cleveland
  • St. Louis
  • Baltimore
  • Cincinnati
  • Raleigh–Durham
  • Columbus
  • Indianapolis
  • Pittsburgh
  • Kansas City
  • Salt Lake City
  • Explore more in the app

The build is delivered remotely and handed over. After handover the deployment runs where you put it, on credentials you hold, under monitoring you already operate.

Sources

  • HIPAA JournalHIPAA business associate agreements and downstream subcontractors. https://www.hipaajournal.com/hipaa-business-associate-agreement/ · read September 3, 2026
  • U.S. Department of Health and Human ServicesBusiness Associates — HIPAA guidance. https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html · read September 3, 2026
  • Federal Trade CommissionSafeguards Rule. https://www.ftc.gov/legal-library/browse/rules/safeguards-rule · read September 3, 2026
  • Baker BottsColorado repeals and replaces its AI Act (SB 26-189). https://ourtake.bakerbotts.com/post/102msga/colorado-repeals-and-replaces-ai-act · read September 3, 2026
  • Norton Rose FulbrightColorado enacts revised AI law. https://www.nortonrosefulbright.com/en-us/knowledge/publications/18733d31/colorado-enacts-revised-ai-law · read September 3, 2026
  • Matthiesen, Wickert & Lehrer, S.C.Recording conversations: a 50-state survey of consent requirements. https://www.mwl-law.com/wp-content/uploads/2018/02/RECORDING-CONVERSATIONS-CHART.pdf · read September 3, 2026

Rules change, and court decisions change them faster than regulators republish. Every statement above was read from the source shown on the date shown. Confirm the current position with your own counsel before relying on it.

FAQ

Questions from US compliance teams

What US compliance and security teams ask before this reaches a review board.

It removes the sub-processor chain, which is usually the expensive part. Under the health information rules a business associate that subcontracts a function involving protected information needs its own agreement with that subcontractor, and those downstream parties are business associates too — a documented chain running back to the covered entity. When the platform runs inside your environment there is no external party in the call path to place on that chain. Your own counsel should confirm what the licensing relationship itself requires, but the recurring assessment burden across multiple processors is what goes away.

The continuing oversight duty is the thing worth costing. The Safeguards Rule requires you to select and retain only service providers capable of maintaining appropriate safeguards, to contract with them to do so, and to assess them periodically — and that obligation stays with you no matter what a vendor asserts. Every additional processor in a call path is therefore a recurring assessment rather than a one-time approval. Removing them removes the recurring work, which over a few years is frequently a larger number than the difference in licence cost.

Control the disclosure and handling directly rather than through a vendor's release cycle. Colorado is the clearest illustration: its 2024 act was repealed and re-enacted in May 2026 with the effective date moved to January 2027 from an already-extended date, and the Attorney General has said enforcement waits on rulemaking. Any organisation whose deployment can only change when a supplier ships is structurally behind that. A self-hosted deployment lets your own team adjust the script and the handling in the same week a rule lands.

Capacity, patching, backups, monitoring and access management — the ordinary cost of running software you control. For an organisation with an established platform team this is usually absorbed without a new hire, and the trade is generally considered worth it because the alternative is an annually recurring vendor assessment. For an organisation without that capability, the honest recommendation is the hosted product with a properly documented review rather than a self-hosted deployment nobody has time to operate.

Yes, and for some organisations that sequencing is the right call: prove the call flows and the value on the hosted product with a limited, non-sensitive set of calls, then move the deployment inside once the business case is settled. What is worth deciding early rather than late is which record systems the agent will eventually need to reach, because the ones that never face the internet are exactly the integrations that will drive the move — and knowing that upfront shapes how the first phase is scoped.

Connect with our experts

Let’s map your calls

Tell us which environment you would deploy into and which record systems the agent needs to reach, and we will scope the architecture and the handover before quoting anything.

Book a discovery call