Keep Call Centers in America Act: Status and Impact

Keep Call Centers in America Act: Is It Law Yet?

ON THIS PAGE

Written by: Matt Beucler, CEO, Plura AI | Last updated: August 26, 2026

Key Takeaways for Contact Center and CX Leaders

  • The Keep Call Centers in America Act (S.2495) is not law and remains stalled in Senate committee with no recorded action since July 2025.
  • The FCC’s March 2026 NPRM proposes a 30% offshore call cap and restricts foreign handling of sensitive consumer data for telecommunications providers.2
  • Five states (New York, New Jersey, Connecticut, Missouri, and Florida) already enforce laws that limit offshore call center operations or sensitive data handling.2
  • High-volume operators face growing compliance pressure from federal proposals and existing state regulations, regardless of the stalled federal bill.
  • Plura AI delivers 100% U.S. infrastructure by architecture to help operators address these emerging requirements. See how Plura’s architecture works in a live walkthrough.

Quick Answer: Status of the Keep Call Centers in America Act

The Keep Call Centers in America Act (S.2495) is not currently law. According to Congress.gov, the bill remains in the Senate Committee on Commerce, Science, and Transportation with no hearing, markup, or vote recorded since its introduction on July 29, 2025. The House companion bill, H.R.4954, is also stalled in committee, and neither chamber has passed either version.

The Problem: Regulatory Exposure for High-Volume Operators

S.2495 was introduced by Sen. Ruben Gallego (D-AZ) with one cosponsor, Sen. Jim Justice (R-WV), and referred to the Senate Commerce Committee on the same day. As of August 2026, both the Senate and House versions remain in committee with no further action recorded. The bill is not law, and no implementation date exists.

S.2495 would create meaningful operational constraints if enacted. Key provisions include:

The bill is stalled. The compliance risk is not.

The FCC’s Notice of Proposed Rulemaking (NPRM) in CG Docket No. 26-52, adopted on March 26, 2026, creates parallel pressure that does not require Congressional action. The NPRM applies to providers of telecommunications service, Commercial Mobile Radio Service (CMRS), and Direct Broadcast Satellite (DBS). It proposes:

  • A cap of approximately 30% on the share of customer service calls handled at foreign call centers.
  • A restriction on offshore handling of sensitive consumer data including passwords, multi-factor authentication information, Social Security numbers, and bank account or credit card information, regardless of communication channel.
  • A ban on using call centers located in foreign-adversary countries, following the Department of Commerce designation list at 15 C.F.R. § 791.4, which includes China, Cuba, Iran, North Korea, Russia, and Venezuela.
  • An amendment to the Broadband Label rule (47 C.F.R. § 8.1) requiring covered broadband providers to display the percentage of customer service calls handled by U.S.-located representatives.

The NPRM is not final law. The U.S. Chamber of Commerce and five state chambers filed June 2026 reply comments arguing the FCC lacks statutory authority to impose these mandates. Operators in covered industries should consult qualified counsel on their specific exposure. The direction of regulatory travel is toward domestic infrastructure, and the comment record continues to build that case.

Given this regulatory trajectory of stalled federal legislation, active FCC rulemaking, and multiple state laws already in force, operators now face a structural infrastructure question that spans all three layers.

The Solution: 100% U.S. Infrastructure by Architecture

Plura AI is an FCC-licensed carrier-grade platform running AI voice agents, AI SMS, AI RCS, and AI webchat on 100% U.S. infrastructure by architecture. Voice origination, model hosting, data storage, and call recording all sit on domestic infrastructure. This setup is not a contractual promise layered on top of a foreign vendor relationship. It is the structural design of the platform.

Screenshot of Plura’s fully compliant AI communications platform showing business registration and phone number provisioning workflows for AI Voice, SMS, RCS, and Webchat communication automation.
Plura’s FCC-licensed AI communications platform simplifies compliant business registration and phone number provisioning for AI Voice, SMS, RCS, and Webchat workflows.

For operators in FCC-regulated industries, that architecture directly addresses the NPRM’s proposed sensitive-data restrictions and offshore-cap concepts. For operators in any industry, it aligns with the state laws already in force and the potential federal legislation that may follow S.2495.

Plura’s platform supports compliance with the following frameworks: SOC 2, HIPAA, ISO certification, GDPR, SHAKEN/STIR caller ID verification, TCPA compliance, and DNC compliance.1 Every outbound contact is checked against federal and state DNC registries in real time before dial. TCPA consent records are timestamped and immutable. Quiet-hours rules enforce automatically through time-zone detection. Customers remain responsible for their own regulatory obligations; Plura provides the infrastructure that supports that posture.

Plura Security & Compliance dashboard highlighting SOC 2, ISO, and GDPR standards with secure trust verification management.
Plura Security & Compliance supports SOC 2, ISO, and GDPR standards with trust registration, verification management, and secure AI communications.

Plura’s AI Predictive Dialer originates calls on Plura’s own FCC-licensed audio bridging carrier with SHAKEN/STIR caller ID verification on every outbound call. The platform’s Stateful Conversation Database holds context across voice, SMS, RCS, and webchat, so every channel inherits the full memory of every prior touchpoint. Compare plans and rates side by side at plura.ai/pricing.

Five States Already Enforcing Onshoring and Data Limits

Federal legislation may be stalled, but state-level enforcement is active. Five states have enacted laws that restrict offshore handling of calls or sensitive consumer data:

  • New York: The Call Center Jobs Act requires advance notice before relocating call center operations and imposes penalties up to $10,000 per day for non-compliance.
  • New Jersey: New Jersey’s Call Center Jobs Act requires notification for staffing reductions or offshore relocation of call center work and imposes related penalties.
  • Connecticut: Connecticut’s General Assembly has enacted state-contract bans restricting offshore handling of state-related call center work.
  • Missouri: An executive order from the Missouri Office of Administration addresses outsourcing of state contracts outside the United States.
  • Florida: Florida Statutes restrict the offshore handling of medical information, creating direct exposure for healthcare operators using foreign infrastructure.

Federal vs. State Rules: Side-by-Side View

The following table summarizes the key provisions of the proposed federal legislation, the FCC NPRM, and enacted state laws. Operators should consult qualified counsel on the specific provisions applicable to their operations in each jurisdiction.

30% offshore threshold triggers federal grant and loan ineligibilityApproximately 30% cap on offshore call volume for covered providers

Jurisdiction Offshore Cap Sensitive-Data Restriction Penalty Structure
S.2495 (Federal, proposed) Not specified in bill text Monthly penalty, suspension of disbursements, loan or grant cancellation after one year on DOL list
FCC NPRM CG 26-52 (Federal, proposed) Passwords, MFA, SSN, bank and card data handled only at U.S. call centers FCC enforcement authority, with gateway bonds up to $100K proposed for foreign robocall deterrence
New York (enacted) No percentage cap, advance notice required before any offshore relocation Not specified Up to $10,000 per day
Florida (enacted) No percentage cap Medical information restricted from offshore handling Per Florida Statutes enforcement provisions

New Jersey, Connecticut, and Missouri have requirements related to the offshore relocation of call center work or state contract outsourcing; operators should consult qualified counsel on the specific provisions applicable to their operations in each state.

What Operators Should Do Now: Three Infrastructure Checks

The following items are infrastructure checks, not legal advice. Operators should consult qualified counsel on their specific regulatory obligations.

  1. Verify 100% domestic voice origination. Confirm that every call your platform originates or terminates routes through a U.S.-based carrier. If your AI voice or dialer vendor routes through a third-party CPaaS with foreign infrastructure dependencies, that routing becomes a potential exposure point under both the FCC NPRM and state onshoring laws. Plura originates voice on its own FCC-licensed audio bridging carrier, with no foreign infrastructure in the path.
  2. Confirm real-time DNC and TCPA compliance enforcement at the carrier level. Many platforms claim DNC and TCPA coverage but run checks after the call has already left the network, which means any violation has already occurred by the time the system flags it. Enforcement before dial is the architecture that prevents those calls from being placed in the first place. Plura’s compliance engine checks every outbound contact against federal and state DNC registries in real time before the call originates, with immutable consent records and one-click audit exports available through the platform.
  3. Ensure all data storage and model hosting remain inside the United States. The FCC NPRM’s sensitive-data concepts apply regardless of communication channel, covering calls, texts, emails, and online chats. If your AI model, call recordings, or customer data touch foreign servers at any point in the workflow, that creates the structural gap these proposals and state laws focus on. Plura’s architecture, described in the earlier section, keeps model hosting, data storage, and call recording on domestic infrastructure.

Run these three checks against your current setup in a live platform audit with Plura.

Frequently Asked Questions

Is the Keep Call Centers in America Act currently law?

No. S.2495 was introduced on July 29, 2025, and referred to the Senate Committee on Commerce, Science, and Transportation, where it remains with no hearing, markup, or vote recorded as of August 2026. The House companion bill, H.R.4954, is similarly stalled in committee. Neither version has passed either chamber or been signed into law.

Does the FCC require U.S.-based call centers?

Not yet. The FCC adopted an NPRM in CG Docket No. 26-52 on March 26, 2026, proposing rules that would cap offshore call volume at approximately 30% for covered providers, restrict offshore handling of sensitive consumer data, and require disclosure when calls are routed outside the United States. The NPRM is a proposal, not a final rule, and it applies to providers of telecommunications service, CMRS, and DBS service. Operators in covered industries should consult qualified counsel on their specific exposure and monitor the FCC docket for final rule publication.

Which industries are most exposed to the FCC NPRM and state onshoring laws?

The FCC NPRM directly targets telecommunications providers, wireless carriers, and satellite service providers. State laws in New York, New Jersey, Connecticut, Missouri, and Florida extend restrictions to healthcare operators, state contractors, and any business relocating call center work offshore. The FCC has also sought comment on whether to extend some or all onshoring requirements to additional service providers beyond the initial covered categories. High-volume operators in healthcare, financial services, insurance, and legal services face some of the broadest combined exposure from both federal proposals and state-enacted rules.

What sensitive data is referenced in the proposed FCC rules?

The FCC NPRM proposes that consumer transactions involving passwords, multi-factor authentication information, Social Security numbers, bank account information, and credit card information be handled only at call centers located within the United States, regardless of the communication channel used. This concept would apply to calls, emails, text messages, and online chats. The proposal also seeks comment on restricting covered providers from using call centers in countries designated as foreign adversaries under the Export Control Reform Act, including China, Cuba, Iran, North Korea, Russia, and Venezuela. These are proposals, not final rules; operators should consult qualified counsel on current obligations.

How does Plura’s infrastructure address offshore compliance exposure?

Plura runs on 100% U.S. infrastructure by architecture, with voice origination, model hosting, data storage, and call recording on domestic infrastructure. Plura is its own FCC-licensed audio bridging carrier, not a wrapper on a third-party CPaaS with foreign infrastructure dependencies. The platform supports the compliance frameworks outlined earlier, including SOC 2, HIPAA, ISO certification, GDPR, SHAKEN/STIR caller ID verification, TCPA enforcement, and DNC enforcement.1 Every outbound contact is checked against federal and state DNC registries in real time before dial. Customers are responsible for their own regulatory obligations and should consult qualified counsel; Plura provides the infrastructure that supports that posture.

Conclusion: Infrastructure as the Long-Term Answer

The Keep Call Centers in America Act is not law, and S.2495 remains in committee with no recorded action since July 2025. The regulatory pressure it represents is already arriving through two parallel channels: the FCC NPRM in CG Docket No. 26-52, which proposes a 30% offshore cap and sensitive-data restrictions for covered communications providers, and five state laws in New York, New Jersey, Connecticut, Missouri, and Florida that already limit offshore handling of calls and sensitive consumer data.

For high-volume operators, 100% U.S. infrastructure by architecture provides a structural response to this environment. Not a contractual promise. Not a third-party vendor attestation. Architecture. Plura’s FCC-licensed carrier-grade platform, described above, runs voice origination, model hosting, data storage, and call recording on domestic infrastructure, with the real-time compliance enforcement and caller ID verification already outlined.

Compare plans and rates side by side at plura.ai/pricing to see how Plura’s infrastructure maps to your volume and compliance requirements.

See how Plura’s FCC-licensed infrastructure maps to your compliance requirements in a live platform demo.


1 Plura AI maintains SOC 2, HIPAA, ISO, and GDPR posture as part of its platform infrastructure. References to compliance frameworks in this article describe Plura’s platform capabilities and do not constitute a guarantee that any customer using Plura will themselves be compliant with applicable laws or standards. Customers remain solely responsible for their own regulatory obligations, certifications, consent management, recordkeeping, and the claims they make to their own end users. Consult qualified legal counsel for guidance specific to your use case.

2 This article describes regulatory frameworks at a general level and does not constitute legal advice. Laws and regulations vary by jurisdiction, change over time, and apply differently depending on facts and circumstances. Readers should consult qualified legal counsel before making compliance decisions.

This article is provided for informational purposes only and reflects Plura AI’s understanding at the time of publication. Product capabilities, integrations, and specifications are subject to change. For the most current information, visit plura.ai.

This article was produced with the assistance of AI tools and reviewed by Plura AI prior to publication.

Read Next

See how Plura AI transforms AI voice agents