Omnifys builds and operates AI agents for US organizations across healthcare, financial services, retail, logistics and professional services. We handle strategy, build, integration and monitoring, and we design around the compliance regime you actually fall under rather than a generic one.

A patchwork, not a framework

There is still no comprehensive federal privacy statute and no comprehensive federal AI statute. As of 2026, roughly twenty states have comprehensive consumer privacy laws in effect, covering more than half the US population — Indiana, Kentucky and Rhode Island joined in January 2026. Binding AI obligations sit almost entirely at state level: California requires large frontier model developers to publish risk frameworks and report safety incidents, and separately requires generative AI developers to publish training data summaries. Texas began enforcing its Responsible AI Governance Act in January 2026, which bans AI systems designed for behavioral manipulation or unlawful discrimination.

A federal preemption effort is live, pushed through executive action and legislative recommendations, but nothing is settled. For most businesses the working assumption should be that you comply with the states you operate in, and that the map changes every January.

How we handle it

  • Deployment scoped to the states you actually operate in, reviewed as new laws take effect.
  • SOC 2-aligned controls on agents touching customer data, with evidence your auditor can use.
  • HIPAA-aligned deployments for covered entities and business associates, including BAA support.
  • Consumer rights request handling — access, deletion, opt-out — wired into the agent rather than bolted on.
  • Decision logging sufficient to answer a discrimination challenge, because that is where enforcement is heading.

Commercial details

Quoted and invoiced in US dollars. SaaS tools from USD 39–99 per month, managed agents USD 500–2,000 per month following a paid pilot, custom builds from USD 5,000. Every managed engagement includes monitoring, model routing across 15+ LLMs, and post-deployment optimization.

Common questions

Which US privacy laws apply to us?

It depends on where your customers are, not only where you are. Around twenty states now have comprehensive privacy laws in effect, and several use different thresholds for who is covered. We map this during discovery and scope the deployment to the states that actually apply to you.

Can you support a HIPAA-covered workload?

Yes. We deploy HIPAA-aligned agents for covered entities and business associates, including business associate agreement support and the access controls and audit logging the Security Rule expects. Tell us at discovery so the architecture accounts for it from the start.

Are you SOC 2 certified?

Omnifys deploys SOC 2-aligned controls and produces the evidence your auditor needs for agents in scope. We are not claiming a completed SOC 2 attestation for Omnifys itself — ask us directly about current certification status rather than assuming, and we will tell you plainly.

Will federal AI preemption change what we have built?

Possibly, but preemption would generally reduce the number of standards you answer to rather than add new ones. Systems built to the stricter state requirements should remain compliant. We track this and will tell you if something material changes.

Talk to us

Book a free consultation and we will map one workflow end to end, tell you honestly whether an agent is the right answer, and quote it in your local currency. Get in touch.

Regulatory summaries on this page were reviewed in July 2026 and are provided for general information only. They are not legal advice. Privacy and AI law is changing quickly in all three markets — confirm your own position with qualified counsel.