The FCC doesn't tend to make too many waves in the CX space.
But a new regulatory proposal from the United States Federal Communications Commission could significantly impact the contact center space moving forward.
Brought forward by FCC Chair Brendan Carr, the ruling would cap the volume of calls handled offshore, mandate disclosure when customers are speaking to agents outside the US, and require that customers can request a domestic transfer.
At first glance, the ‘why?’ seems fairly transparent.
Companies will be forced to bring more jobs back to America, which resonates with Carr’s broader Build America Agenda.
However, when you scratch beneath the surface, it becomes something more complicated – and more interesting, as Zeus Kerravala, Principal Analyst at ZK Research, explains:
“On the surface, you can look at them as labor economics. But they're also about data security, national security, and customer service.”
“And when you look at your side of the pond [the UK], everyone's got data sovereignty rules in place. So, I don't think this should really be that big a surprise.”
What Kerravala is pointing to is something the headline numbers on this proposal tend to obscure.
The most consequential aspect isn't necessarily the cap on offshore call volumes; it's the explicit connection the FCC is drawing between customer experience quality, national security, and fraud prevention as a single, interconnected concern.
That's a different regulatory lens than the US CX industry has operated under before, and it has implications that stretch well beyond compliance departments.
The Stakes Are Real
The offshoring model has been a cornerstone of contact center strategy for a long time –and for good reason.
By offshoring contact center operations to the likes of India and the Philippines, US companies are able to lower labor costs and scale headcount, while providing around-the-clock coverage.
According to Kerravala, the FCC proposal doesn't just complicate those economics. For some sectors, it could threaten them entirely:
“I was talking to a company that runs a gambling site, and their margins are so thin that they offload everything because it just helps them with profitability.
“But there's a good example – a gambling site dealing with credit card information, payment information, that probably should be onshore.”
That example gets at what this regulation is actually targeting. The issue isn't offshore labor in the abstract; it's the fact that data handling controls across international outsourcing arrangements are, at best, inconsistent
In sectors that routinely handle financial, healthcare, or identity data, the question of where that information travels and who can access it has been easier to ignore than to address.
The FCC is making that harder to ignore.
8x8 CEO Samuel Wilson was among the first vendor executives to respond publicly. In a LinkedIn post that drew significant engagement across the industry, Wilson framed the regulation as something bigger than a compliance event:
“The FCC is explicitly connecting customer experience quality, national security, and fraud prevention.
“That's a different lens than we've seen before. It suggests that 'where' and 'how' service is delivered may soon matter as much as 'how much it costs.’”
His conclusion was pointed: “You can outsource the work. You can't outsource the accountability.”
The Compliance Question Lands on IT's Desk
Historically, regulatory compliance in customer service has often been treated as someone else's problem – be that the legal team's, the compliance function's, or even occasionally the CFO's.
This proposal changes that dynamic, because the practical mechanics of adhering to these rules are fundamentally a technology and infrastructure problem.
Take the FCC's proposed requirement for automated tracking of offshore and onshore call volumes to ensure compliance with whatever cap is eventually set.
Manually auditing that across thousands of daily interactions isn't realistic. The tools to do it at scale – AI-driven call routing, PII redaction systems, automated volume tracking – live inside the technology stack, not the legal department.
Kerravala is direct about where responsibility should land, claiming that he is “not sure that lawyers involved in this fully understand the scope of what AI can do. And so by taking that back and making it an IT function, I think IT can have better control over that thing to make sure that companies aren't failing to adhere.”
He specifically points to instances such as shifting password resets and MFA updates to domestic AI agents as examples where compliance requirements can be satisfied without the cost overhead of adding domestic human headcount
AI-driven PII redaction can mask sensitive information before it ever reaches an offshore agent. Automated routing logic can trigger domestic-only handling when offshore caps are being approached.




