Written by: Matt Beucler, CEO, Plura AI | Last updated: August 28, 2026
Key takeaways for contact center leaders
- S.2495 remains stalled in the Senate Commerce Committee with no hearings or markup scheduled before the 119th Congress ends in January 2027.
- Five states already enforce their own call-center onshoring laws that apply regardless of federal action.
- The FCC’s March 2026 NPRM proposes a 30% offshore volume cap, sensitive-data restrictions, and foreign-adversary-nation bans that would reshape vendor strategies.
- AI platforms built on 100% U.S. carrier infrastructure avoid the offshore caps and disclosure mandates that affect traditional BPOs and CPaaS resellers.
- Operators can book a live demo with Plura AI to map their current infrastructure against these emerging rules and quantify the savings of moving to 100% U.S. AI.
Current status of the Keep Call Centers in America Act
S.2495 has not passed. S.2495, introduced by Sen. Ruben Gallego (D-AZ) on July 29, 2025, with one cosponsor (Sen. Jim Justice, R-WV), has recorded no action beyond its referral to the Senate Committee on Commerce, Science, and Transportation. The House companion, H.R.4954, introduced by Rep. Kristen McDonald Rivet (D-MI-8) on August 12, 2025, has attracted 12 cosponsors and was referred to four House committees. Its latest recorded action also remains that initial referral.
As of August 4, 2026, neither chamber version has received a committee hearing or markup in the 119th Congress.
If enacted, the bill would require call-center agents to disclose their location at the start of a call. It would grant consumers the right to demand transfer to a U.S.-based human agent, including when an AI system is handling the call. It would also place companies that move call-center work offshore on a Department of Labor list barring new federal grants and guaranteed loans for up to five years.
Likelihood of passage before the 119th Congress ends
The odds of passage before January 2027 are low based on current activity. The 119th Congress ends in early January 2027, leaving roughly four months of legislative calendar. S.2495 has not cleared a single procedural step beyond introduction. No committee hearing has been announced, no markup has been scheduled, and no floor time has been allocated.
For context, S.2, the Secure America Act, became Public Law No. 119-98 on June 10, 2026, because it moved as a reconciliation vehicle under a budget resolution. That process bypassed the filibuster and compressed the timeline. S.2495 carries no comparable procedural vehicle and no leadership-prioritized attachment.
The 2026 midterm election cycle further compresses available floor time in the fall. One year after introduction, the bill has generated considerably more discussion than legislative action. Passage before January 2027 would require an acceleration that has no current evidence of momentum.
State onshoring rules that already apply
Five states have active laws or executive orders that restrict offshore handling of consumer data or impose disclosure and operational requirements on contact center operators, independent of any federal bill:
- New York: The Call Center Jobs Act requires employers to notify the state before relocating call-center operations offshore and imposes penalties up to $10,000 per day for non-compliance.
- New Jersey: A mirror statute imposes comparable notification and penalty requirements on employers moving call-center work out of state.
- Connecticut: The Connecticut General Assembly has enacted state-contract bans that restrict offshore call-center use by vendors serving state agencies.
- Missouri: An executive order from the Missouri Office of Administration requires offshore-disclosure practices for state-contracted vendors handling Missouri residents’ data.
- Florida: Florida statutes restrict the offshore handling of medical information, creating direct exposure for healthcare-adjacent operators using offshore vendors.
Separately, the FCC (Federal Communications Commission) adopted a Notice of Proposed Rulemaking (NPRM) on March 26, 2026, under CG Docket No. 26-52. The NPRM proposes a 30% cap on offshore customer-service call volume, mandatory “handled abroad” disclosures at the start of each call, a consumer right to transfer to a U.S.-based agent, a ban on offshore handling of sensitive data (including Social Security numbers, passwords, multi-factor authentication codes, credit card data, and Customer Proprietary Network Information), and a prohibition on using call centers in foreign adversary nations including China, Cuba, Iran, North Korea, Russia, and Venezuela.
The NPRM also proposes amending broadband consumer label rules to require disclosure of the percentage of customer-service calls handled by U.S.-based representatives. These are proposals, not final rules, and operators should consult qualified counsel on their specific obligations.

California and Florida also require all-party consent for call recording under state law.2 Federal law requires only one-party consent, which creates jurisdiction-specific disclosure workflows for multi-state contact centers. The Telephone Consumer Protection Act (TCPA), 47 U.S.C. § 227, imposes penalties of $500 to $1,500 per call for violations involving outbound calls, texts, or prerecorded messages without prior express written consent.2
Map your current vendor stack against these state and federal requirements in a live demo with Plura.
Regulatory impact on AI platforms and BPO vendors
Regulatory exposure now depends heavily on how your contact center infrastructure is deployed. The exposure profile differs significantly between offshore business-process outsourcing (BPO) vendors and AI platforms, and within AI platforms, between those that own their carrier infrastructure and those that do not.
Offshore BPOs face the most direct exposure. The FCC NPRM’s proposed 30% offshore volume cap, sensitive-data prohibition, and foreign-adversary-nation ban would require structural redesign of routing, staffing, and data-handling models for any operator relying on offshore BPO capacity. State laws in New York, New Jersey, Connecticut, Missouri, and Florida already impose penalties and restrictions that apply regardless of whether the NPRM becomes final.

AI platforms built as API resellers on top of third-party Communications Platform as a Service (CPaaS) providers, such as Twilio, carry a different but real exposure.4 If the underlying carrier infrastructure routes through foreign data centers or foreign-owned network nodes, the platform may not satisfy a “U.S.-handled” standard under the FCC NPRM’s proposed broadband label disclosure rules. These platforms also typically cannot enforce real-time Do Not Call (DNC) scrubbing or TCPA-litigator filtering at the carrier level, because they do not own the carrier.
Platforms that own their carrier stack occupy a structurally different position. Because voice origination, model hosting, data storage, and call recording sit entirely on domestic infrastructure, these platforms fall outside the proposed offshore restrictions. No volume cap applies, no sensitive-data prohibition triggers, and no foreign-adversary-nation ban is relevant under the NPRM as currently drafted.
A Gartner April 2026 survey found that 80% of service and support leaders feel pressure to make workforce changes as AI reduces contact volume, and 85% are expanding human agent responsibilities.4 Regulatory pressure now functions as a planning variable alongside cost and capacity, not as a separate compliance exercise.
Action checklist for contact center operators
The following checklist reflects the actions contact center leaders, compliance officers, and CX executives are taking in response to the current regulatory environment, independent of whether S.2495 passes:
- Audit your vendor’s infrastructure geography. Identify whether voice origination, model hosting, data storage, and call recording sit on U.S. or foreign infrastructure. CPaaS-dependent AI platforms may route through foreign nodes without disclosing it.
- Map sensitive-data flows. Identify every interaction type that involves Social Security numbers, passwords, multi-factor authentication, credit card data, or protected health information (PHI). Under the FCC NPRM as proposed, these interactions would be prohibited from offshore handling.
- Review state-law exposure. If your operation serves customers in New York, New Jersey, Connecticut, Missouri, or Florida, or if you hold state contracts in Connecticut, consult qualified counsel on current obligations under those states’ active statutes.
- Assess your broadband consumer label disclosures. If you are a covered communications provider, the FCC NPRM proposes requiring disclosure of the percentage of customer-service calls handled by U.S.-based representatives. Model what that disclosure would look like under your current vendor mix.
- Model the cost of transition before it becomes mandatory. Operators who wait for a final rule to restructure vendor relationships face compressed timelines and higher transition costs. Running the numbers now, while the NPRM is still in comment, preserves optionality.
- Evaluate AI platforms by carrier ownership, not marketing claims. Platforms that own their carrier infrastructure can enforce compliance controls, including branded caller ID, real-time DNC scrubbing, and STIR/SHAKEN (Secure Telephone Identity Revisited/Signature-based Handling of Asserted information using toKENs) authentication, at the network level before a call reaches an agent or AI system. CPaaS resellers inherit the posture of their underlying carrier and have limited ability to customize or enforce controls in real time.
Plura AI is an FCC-licensed audio bridging carrier running on 100% U.S. infrastructure. The platform enforces the carrier-level controls described above, including branded caller ID, real-time DNC scrubbing, TCPA-litigator filtering, and STIR/SHAKEN authentication, before each outbound contact reaches a prospect. The AI voice agent, AI Predictive Dialer, AI SMS, and AI webchat channels share a single Stateful Conversation Database, so every interaction is keyed to the same customer record across channels. Plura supports compliance with TCPA, DNC, HIPAA, SOC 2, and 50+ state rule sets; customers remain responsible for their own regulatory obligations and certifications.1

Operators using Plura report “100% U.S.-handled” in their broadband consumer label disclosures. The platform’s managed workflows and conversation intelligence layer provide the audit-ready reporting that compliance teams need when regulators or procurement officers ask for documentation.
See how your current infrastructure measures against the FCC’s proposed offshore caps and sensitive-data restrictions, then schedule a demo with Plura.
Frequently asked questions on S.2495 and the FCC NPRM
Will the Keep Call Centers in America Act become law in 2026?
Based on the bill’s current position, passage before the 119th Congress ends in early January 2027 appears unlikely. S.2495 has not received a committee hearing, markup, or floor vote since its introduction on July 29, 2025. No legislative vehicle has been identified to accelerate it.
Operators planning vendor decisions should not assume the bill will pass on any specific timeline. They should, however, account for the regulatory pressure that already exists through state laws and the FCC NPRM.
Does S.2495 apply to AI voice agents?
As written, S.2495 would require disclosure of agent location at the start of a call and would grant consumers the right to transfer to a U.S.-based human agent, including when an AI system is handling the call. The bill does not exempt AI-handled interactions from its disclosure or transfer requirements.
Operators deploying AI voice platforms should review the bill text and consult qualified counsel on how its provisions would apply to their specific deployment model if enacted.
Does the FCC NPRM apply to AI platforms, not just traditional call centers?
The FCC’s March 2026 NPRM under CG Docket No. 26-52 proposes rules for communications service providers and seeks comment on expanding jurisdiction to non-interconnected VoIP, internet, text, and chat providers, and to TCPA-covered calls. The NPRM’s proposed sensitive-data prohibition and offshore volume cap would apply based on where interactions are handled and where data is processed, not based on whether the interaction is AI-handled or human-handled.
Operators using AI platforms with foreign infrastructure dependencies should assess their exposure and consult qualified counsel.
What is the difference between the FCC NPRM and S.2495?
The FCC NPRM (CG Docket No. 26-52) is a regulatory proceeding initiated by the Federal Communications Commission under its existing statutory authority. It proposes rules that, if finalized, would have the force of law without requiring congressional action. S.2495 is a bill that requires passage by both chambers of Congress and presidential signature to become law.
The two tracks operate independently. The NPRM can advance, stall, or be finalized regardless of what happens to S.2495, and vice versa. Operators face potential obligations from both tracks on different timelines.
How does 100% U.S. infrastructure reduce regulatory exposure compared to offshore BPOs?
Under the FCC NPRM as proposed, offshore call-center volume would be capped at 30% of interactions, sensitive consumer data could not be handled offshore, and call centers in foreign adversary nations would be prohibited entirely. An operator running on 100% U.S. infrastructure by architecture does not route interactions through foreign infrastructure, so the proposed offshore volume cap, sensitive-data prohibition, and foreign-adversary-nation ban do not apply in the same way.
Offshore BPO operators would need to restructure routing, staffing, and data-handling models to align with the NPRM if it is finalized. Operators should consult qualified counsel on how these proposals apply to their specific vendor relationships and contracts.
Calculate the cost of staying exposed
The regulatory environment around call-center onshoring is not resolved by S.2495’s stalled status. The FCC NPRM is active, and state laws in five states are already in force. The cost of restructuring vendor relationships under a compressed post-rule timeline is higher than the cost of modeling the transition now.
Plura’s ROI calculator lets operators run the numbers on what 100% U.S. AI infrastructure costs against their current human or offshore model. A 15-agent operation paying $20 per hour with standard overhead costs $60,000 per month. The same volume on Plura’s platform runs at $14,400 per month, with 100% talk utilization and no rehiring cycle. That is $45,600 in 30-day savings, $547,200 over 12 months, and $2,736,000 over 60 months, based on the default scenario at plura.ai/calculator.3
Use Plura’s calculator to model your own costs and ROI in real time.
1 Plura AI maintains SOC 2, HIPAA, ISO, and GDPR posture as part of its platform infrastructure. References to compliance frameworks in this article describe Plura’s platform capabilities and do not constitute a guarantee that any customer using Plura will themselves be compliant with applicable laws or standards. Customers remain solely responsible for their own regulatory obligations, certifications, consent management, recordkeeping, and the claims they make to their own end users. Consult qualified legal counsel for guidance specific to your use case.
2 This article describes regulatory frameworks at a general level and does not constitute legal advice. Laws and regulations vary by jurisdiction, change over time, and apply differently depending on facts and circumstances. Readers should consult qualified legal counsel before making compliance decisions.
3 Performance figures, customer outcomes, and industry statistics referenced in this article are drawn from cited third-party sources or Plura customer case studies. Individual results vary based on implementation, use case, industry, audience, and execution. Past or aggregate performance is not a guarantee of future results.
4 References to third-party products, services, companies, or research are made for informational and comparative purposes only. Plura AI is not affiliated with, endorsed by, or sponsored by any third party named in this article unless explicitly stated. Trademarks and product names referenced remain the property of their respective owners.
This article is provided for informational purposes only and reflects Plura AI’s understanding at the time of publication. Product capabilities, integrations, and specifications are subject to change. For the most current information, visit plura.ai.
This article was produced with the assistance of AI tools and reviewed by Plura AI prior to publication.