Arkansas buyer guide

Outsourcing software development from Arkansas

An Arkansas buyer guide to overseas software and AI delivery: input rights, direction and control, human decisions, cybersecurity, incidents, and exit.

For: Arkansas founders, product and engineering leaders, private employers, public entities, security teams, legal and procurement owners, and operations leaders evaluating software, data, or AI delivery outside the United StatesBy Outsourcing.ai Editorial Team
The decisionAn Arkansas buyer using an international software or AI team should operate a direction-to-decision custody ledger. For each consequential artifact or model, prove who supplied each input and directive, whether the material was lawfully acquired, which entity and contract controlled the work, what the system produced, who evaluated it, which authorized human made the final decision, how security and incident evidence was preserved, and whether the buyer can continue after supplier exit.Evidence references: [1][2][3][4][5][6][7][8][9][10]
Abstract input records passing through provenance and direction gates into a model chamber, evaluation gate, buyer-owned decision console, separate incident archive, and portable exit package
An Arkansas direction-to-decision custody ledger connects lawful inputs, accountable direction, the exact model result, meaningful evaluation, buyer-owned final authority, incident evidence, and a usable exit package without collapsing those facts into one ownership claim. Original Outsourcing.ai editorial illustration, generated with AI and reviewed for relevance and accuracy.
No local-office claim. Outsourcing.ai is an online research and delivery platform. This guide is for Arkansas-based buyers; it does not represent an Arkansas office, local staff, completed Arkansas client work, public-sector authorization, legal ownership determination, copyright registration, cybersecurity approval, regulatory approval, or legal, privacy, security, employment, tax, financial, procurement, or intellectual-property advice.
Direct answerAn Arkansas buyer can use an international team for software, data, and AI work, but generative-AI custody should be proved from input to decision. Create a buyer-owned direction-to-decision ledger for each material artifact, trained model, or consequential workflow. Identify the lawful source of every important input, who gave the directive, whether a worker acted within assigned scope and under the contracting entity's direction and control, the exact output or model produced, pre-existing rights and license limits, tests and human review, the person authorized to accept or act, security and incident evidence, and the export needed at termination. For Arkansas public-entity work, do not substitute a provider or automated tool for the authorized human final decision required by the entity's policy.

Arkansas outsourcing at a glance

Proposed workDefault custody laneEvidence before acceptance or use
Ordinary application, integration, infrastructure, or automation with no generative-AI componentStandard software delivery under buyer-owned repository, acceptance, security, continuity, and exitScope, named entity and team, architecture, source, dependencies, tests, release record, accepted outcome, runbook, rights schedule, and handover
Prompted text, code, image, audio, design, research, or other generated contentInput-and-directive ledger plus output reviewInput source, directive author, approved tool and account, purpose, retention and training settings, generated object, similarity and rights review, edits, accepted version, approver, and license record
Fine-tuned, adapted, trained, or evaluated modelTraining-custody ledger plus model and data lineageLawful data acquisition, provider and license terms, contributor rights, transfer terms, dataset/version, training configuration, model identifier, evaluation, limitations, deployment decision, export, and deletion
Employee or supplier personnel use generative AI as part of assigned workDirection-and-control packet tied to the actual employer and contract chainEmployer or contracting entity, assignment, scope, directing person, approved workflow, supervision, work records, tool account, output, acceptance, exceptions, and country-specific rights evidence
AI or automated decision tool for an Arkansas public entityAuthorized-use and human-final-decision laneEntity policy, permitted purpose, trained users, system and data boundary, recommendation record, meaningful human review, authorized decision maker, reasons, override, appeal or correction route, security, and retention
State-agency technology or dataContract-activated cybersecurity and governance laneApplicable State Cybersecurity Office and agency requirements, data classification, design controls, assessment, remediation, monitoring, logging, incident plan, access, audit evidence, recovery, and exit
Suspected acquisition of Arkansas personal informationImmediate fact relay and separate breach-decision recordDiscovery time, owner/maintainer role, systems, data elements, readability, people, acquisition evidence, containment, risk analysis, decision, notices, Attorney General threshold analysis, five-year evidence custody, and recovery
Nearshore or offshore team comparisonNamed-team and named-city evaluation after custody is definedLegal entities, people, locations, assignments, overlap, demonstrated work, secure delivery, AI-tool policy, rights chain, complete cost, incident response, continuity, and exit exercise

The state-specific issue is not that every Arkansas business uses generative AI or works for government. It is that Arkansas now supplies unusually direct statutory signals about the person providing AI input or direction, the effect of work performed within employment scope and employer control, and the authorized human final decision in public-entity use. A useful outsourcing operating model turns those signals into evidence without pretending they answer every federal, destination-country, copyright, contract, or fact-specific question.

Classify the work before discussing ownership

“AI development” is too broad to assign rights or authority. One engagement may include ordinary source code, third-party libraries, prompted content, customer data, a fine-tuned model, an external model API, a retrieval index, evaluation records, and human decisions. Each object can have a different source, license, contractual owner, controller, custodian, and acceptance path.

Classify at least these objects:

  1. Pre-existing buyer material. Source, documents, product data, designs, brands, processes, instructions, examples, and datasets the buyer supplies. Record the buyer’s rights and the exact permitted use.
  2. Pre-existing supplier material. Frameworks, templates, tools, models, libraries, prompts, evaluation harnesses, and know-how the supplier brings. List exclusions and licenses before they become embedded.
  3. Third-party material. Open-source packages, commercial assets, datasets, model APIs, training services, connectors, and generated dependencies. Preserve the applicable version and terms rather than a homepage link.
  4. Human-created project work. Code, specifications, designs, documentation, labels, tests, analyses, and decisions created without treating an AI output as the final work.
  5. Generated content. A particular output produced from a particular input and directive by a particular tool configuration. Preserve the accepted object, not every disposable experiment unless risk requires it.
  6. Training inputs and resulting model. Data, labels, examples, instructions, weights, adapters, checkpoints, configuration, evaluation, and deployment artifacts. Separate data custody from model custody.
  7. Recommendation and final decision. The system’s output, the information visible to the reviewer, the reviewer, the action taken, and the reason. A recommendation is not the same object as a decision.
  8. Security and incident evidence. Identities, access, logs, alerts, affected systems, forensic material, determinations, notices, recovery proof, and retained supporting documentation.

Do not let a master “all work product” clause replace the inventory. The contract should say what transfers, what remains pre-existing, what is licensed, what third-party terms survive, when acceptance occurs, what cannot be reused, and what must be exported or deleted. The operating ledger proves that the agreed treatment actually reached each material object.

Arkansas Act 927 does not eliminate this work. Its text ties stated outcomes to facts such as who provided an input or directive, whether training data was lawfully acquired, whether rights were transferred by contract, and—when an employee uses a tool—whether use was within employment scope and under employer direction and control. It also does not grant ownership over material infringing pre-existing rights. Those are evidence questions, not labels a provider can settle by writing “AI-assisted” in an invoice.

Build one direction-to-decision custody ledger

The ledger is a versioned buyer record that joins evidence otherwise scattered across contracts, repositories, model platforms, tickets, chats, and approval meetings. Create an entry when a generated artifact or model becomes material to a deliverable, release, customer communication, operational process, or consequential decision.

Ledger layerQuestion the buyer must be able to answerMinimum evidence
Purpose and objectWhat exact artifact, model, recommendation, or decision is in scope?Stable ID, work package, intended use, excluded use, consequence class, system, release or decision link
Input custodyWhat entered the tool or training process, from where, and under what right?Source, collector/provider, date, license or permission, lawful-acquisition basis, confidentiality class, personal-data status, allowed purpose, retention
DirectionWho supplied the operative instruction and for which entity?Named person, employing or contracting entity, directive or prompt version, assignment, scope, approval, deviations
Tool and processWhat actually transformed the input?Provider, product/model/version, account, region, settings, training/retention terms, plugins, retrieval sources, code and configuration, subprocessors
ResultWhat exact object was produced or trained?Immutable output/model ID, files or digest, dependencies, checkpoint, generated date, link to source/input lineage, rejected variants where material
ReviewWhat was tested, compared, corrected, or rejected?Acceptance criteria, evaluator, test dataset, baseline, security and rights checks, factual review, limitations, changes, result
DecisionWho had authority to accept, deploy, publish, or act?Named authorized human, information presented, date, decision, reasons, overrides, conditions, appeal/correction path where applicable
Security and incidentCould unauthorized access, acquisition, manipulation, or disclosure affect the object or decision?Identities, access logs, provenance, alerts, investigation, containment, decision owner, record-retention link, recovery evidence
ExitCan the buyer use, verify, change, replace, or retire the result without the supplier?Export format, source/configuration, model/data rights, credentials, runbook, knowledge transfer, deletion/return evidence, replacement test

Use the ledger as an index, not a warehouse for secrets. A record can point to restricted evidence with access controls and retention rules. Avoid copying full customer datasets, private prompts, credentials, model weights, or investigation details into broad project systems merely to make the entry appear complete.

Fail the gate when identity breaks. A different model version, provider region, system prompt, retrieval corpus, dataset, adapter, safety setting, postprocessor, contributor entity, or acceptance owner can change the result and its custody. The team may approve a targeted update, but it should not silently reuse evidence for a different object.

Prove that inputs were lawfully available for the stated use

Possession is not permission. A supplier may be technically able to scrape a site, export a customer database, upload a document set, or purchase a dataset while lacking the rights needed for training, generation, redistribution, or the buyer’s intended use. Ask for a field-level or collection-level provenance schedule before material enters an AI workflow.

For each source, record:

  • the natural person or legal entity that collected, created, licensed, purchased, or supplied it;
  • the original context and purpose;
  • contractual, statutory, confidentiality, privacy, publicity, copyright, database, employment, or customer restrictions identified by qualified owners;
  • whether training, retrieval, evaluation, prompt input, output publication, adaptation, or commercial use is permitted;
  • geographic, product, audience, time, and transfer limits;
  • personal, biometric, confidential, export-controlled, regulated, or sensitive categories;
  • required attribution, notice, consent, security, deletion, or access handling;
  • downstream model-provider terms, retention, human review, and improvement use;
  • evidence date, reviewer, uncertainty, and recheck trigger; and
  • the decision to include, transform, minimize, synthesize, segregate, or exclude it.

Do not accept “public data” as a rights category. Public visibility may coexist with copyright, site terms, privacy, confidentiality, publicity, contractual, or purpose restrictions. Do not accept “customer-owned” without identifying the contracting customer and the permissions it actually received.

Build a quarantine route for unclear material. The supplier can describe the proposed source and needed function without loading the data. The buyer can replace it with synthetic or licensed material, obtain permission, narrow the use, or reject it. That is cheaper than discovering after training that the team cannot prove what entered the model.

For retrieval-augmented systems, preserve source and access identity at query time. A document that was permitted in an internal repository does not become appropriate for every prompt, user, model provider, log, or generated answer. Enforce document-level permissions, minimize prompt context, prevent cross-tenant retrieval, test citations and access revocation, and record the indexes and connectors used by the accepted system.

Make direction and control operational

An invoice from an agency does not prove which employer directed a contributor, what work was in scope, or whether the person used an approved tool under control. International delivery adds employment, contractor, agency, employer-of-record, subcontract, and local-law questions that an Arkansas buyer should resolve for the actual people and countries.

Maintain a contributor schedule containing:

  • legal name or internal identifier and verified person identity;
  • employing or contracting entity and every intermediary;
  • work country and city, with any remote-work location limits;
  • role, assigned work package, authority, and start/end dates;
  • confidentiality, invention, software, content, data, model, and generated-output terms applicable to that relationship;
  • buyer-to-supplier agreement and documented flow-down;
  • approved repositories, model tools, accounts, devices, workspaces, and data;
  • manager or director who may issue binding project instructions;
  • review and acceptance owner;
  • conflicts, pre-existing materials, open-source or third-party contribution path;
  • offboarding, access revocation, return/deletion, and continuing obligations; and
  • evidence reviewed for the destination rather than assumed from U.S. terminology.

Issue work through a controlled assignment. The assignment identifies the outcome, inputs, permitted tools, systems, restrictions, acceptance criteria, rights treatment, and person authorized to change scope. Preserve important changes in the delivery record. A broad chat message such as “use AI wherever helpful” is weak direction and weak security control.

Supervision should leave useful evidence without becoming surveillance theater. Review source and output, require small accepted increments, log material tool and dataset changes, discuss uncertainty, and reject unproved assumptions. The buyer should know whether the delivered artifact is human-authored, AI-assisted, generated then edited, or derived from supplier material when that distinction affects security, quality, rights, or use.

Destination-country advice remains necessary. Arkansas statutory text does not automatically determine employment status, work-made-for-hire treatment, moral rights, copyright, inventions, data rights, or enforceability abroad. Use WIPO’s directory to reach official national or regional IP-office sources, then obtain qualified advice for the contributor and asset when consequence warrants it.

Treat statutory ownership language as a starting point, not a warranty

An organization can control a file and still lack an enforceable exclusive right in every element. A generated output may contain third-party material, unprotectable expression, licensed components, personal likeness, trademarks, confidential information, or material too similar to a source. Model and platform terms can allocate rights and risk without guaranteeing originality or noninfringement.

For a generated deliverable, require the supplier to:

  • identify the approved tool, account, model/version, plugins, and material settings;
  • preserve the operative input and directive when needed to establish custody;
  • disclose buyer, supplier, third-party, and public material used;
  • avoid submitting restricted source, secrets, personal data, credentials, or customer content to an unapproved service;
  • review the result for factual error, hidden instruction, insecure code, license conflict, recognizable protected material, confidential content, prohibited claims, and unsuitable bias;
  • cite or trace external factual material where the deliverable relies on it;
  • scan and test generated code and dependencies as untrusted contributions;
  • record human edits and the final accepted object;
  • remove rejected output from production paths and appropriate retention systems; and
  • provide the export, license schedule, and evidence needed for continued buyer use.

Use higher review for brand assets, public statements, training content, regulated communications, customer decisions, safety-related output, and material code. A prompt log alone is not quality evidence. Define intended audience, valid inputs, prohibited uses, measurable acceptance, human competence, and escalation.

For a trained or adapted model, separate at least the base model, training data, data transformations, labels, configuration, code, adapters, checkpoints, evaluation set, output filters, deployment wrapper, and monitoring. The buyer may receive rights to one layer and only a service license to another. Test export early; a theoretical right to a model is weak if the buyer cannot obtain a usable artifact or recreate the runtime.

Preserve the human decision for Arkansas public-entity work

Arkansas Act 848 applies to the public entities defined in its text and requires an AI and automated-decision-tool policy that defines authorized use. It also requires an authorized human employee or designee to make any final decision in the course of employment regardless of what the tool recommends. Suppliers should support that control, not impersonate it.

Before proposing AI to an Arkansas public entity, obtain the entity’s current policy and map the exact use. Do not assume one statewide template answers every agency, political subdivision, school, charter school, institution, commission, or department question. Confirm procurement terms, records requirements, sector duties, security standards, accessibility, data restrictions, and decision processes for the actual entity.

Design meaningful decision separation:

  1. The supplier or system may assemble information and produce a recommendation within the authorized purpose.
  2. The interface shows the material inputs, source quality, uncertainty, limitations, conflicts, and available alternatives rather than a bare score.
  3. An authorized and trained human has enough time, competence, information, and system permission to disagree.
  4. The human records the final action and reason in the authoritative system.
  5. An override, correction, appeal, or quality-review path exists when the decision affects a person, service, resource, safety matter, or other consequential outcome.
  6. Monitoring tests whether people are merely rubber-stamping recommendations and whether error differs across meaningful conditions.

Do not let the supplier’s employee become the public entity’s unidentified “human in the loop.” Confirm who the authorized employee or designee is, what delegation is permitted, and who remains accountable. A provider can explain the model, investigate an anomaly, prepare evidence, or administer an approved system without making the entity’s final decision.

Keep recommendation and decision records linkable but distinct. Record the model and version, inputs, recommendation, confidence or limitations, information displayed, reviewer, final decision, reason, override, and later correction. If sensitive or protected records cannot be placed in the project ledger, preserve a stable reference and custody owner.

Activate state cybersecurity controls only for the work that requires them

Arkansas Act 489 gives the State Cybersecurity Office duties for state-agency cybersecurity and information security, including governance, data classification and design controls, breach notification, threat detection and monitoring, assessments, remediation, training, auditing, incident response, and recovery. That does not turn every private Arkansas outsourcing project into State work.

For a state-agency engagement, identify the exact policies, standards, contract clauses, architecture decisions, data classifications, system boundaries, and agency responsibilities that apply. Flow requirements to every subcontractor and service. Require evidence from the proposed environment, not a general claim that the supplier is “compliant with Arkansas.”

Create a contract-control matrix with:

  • requirement and authoritative source;
  • affected system, data, work package, environment, and entity;
  • buyer owner and supplier performer;
  • technical and process implementation;
  • evidence produced, location, sensitivity, and retention;
  • assessment and remediation route;
  • change trigger;
  • incident contact and authority;
  • recovery objective and tested procedure; and
  • exit, return, deletion, and continuing support.

Separate public-safe evidence from restricted security material. A project status may show that an assessment occurred and findings are being handled without exposing vulnerabilities, configurations, threat indicators, or response details to every participant. Define who may see the restricted annex and how the delivery team receives only the actions needed for its work.

For all buyers, NIST’s SSDF provides a useful shared evidence vocabulary. Require protected development environments, component and release provenance, tracked security requirements and design decisions, secure build and release, vulnerability intake and response, and continuous improvement. Tailor the evidence to consequence; do not request a stack of irrelevant documents that no decision owner reads.

Keep the breach-decision record separate and retrievable for five years

Arkansas’s Personal Information Protection Act amendments include a particularly useful operating signal for supplier contracts: a maintainer of computerized data it does not own must notify the owner or licensee immediately following discovery under the stated unauthorized-acquisition condition. The amendments also require the person or business to retain its written breach determination and supporting documentation for five years, with a specified Attorney General request path.

Do not treat those provisions as one universal incident timer or assume every security event is a covered breach. Build a rapid supplier-to-buyer fact relay, then preserve the accountable owner’s separate determination.

The first supplier signal should contain what is known without waiting for a finished report:

  • discovery time and observer;
  • affected account, device, service, environment, repository, model, dataset, or integration;
  • suspected start, current state, and containment already taken;
  • whether the supplier owns the information or maintains it for another entity;
  • categories of information possibly involved, including biometric or authentication material;
  • evidence of access, acquisition, copying, alteration, disclosure, model ingestion, or uncertainty;
  • affected people, customers, tenants, and locations if known;
  • identities, credentials, providers, subprocessors, and countries involved;
  • logs and artifacts preserved and actions that could destroy evidence;
  • immediate operational, safety, fraud, privacy, and decision-integrity risks; and
  • next update time and named incident contacts.

The buyer’s authorized incident and legal owners decide applicability, scope, risk, affected residents, notices, Attorney General reporting, communication, and retention with qualified advice. The supplier supports facts and containment but should not publish a legal conclusion or contact people or authorities unless the contract and incident command expressly authorize it.

Create the written determination even when the conclusion is that notice is not required. Link supporting evidence, assumptions, unknowns, qualified reviewers, approval, date, and any later correction. Apply a five-year hold appropriate to the Arkansas requirement while reconciling longer contractual, litigation, insurance, sector, or legal holds and minimizing unrelated data. Store it somewhere the buyer can retrieve after supplier termination.

Exercise the path. Inject a suspicious export from a model-training bucket or retrieval index. Measure time to disable the identity, preserve provider and application logs, identify data and ownership roles, establish model exposure, notify the buyer, produce staged updates, reach the decision owners, record a determination, restore safely, and retain the final evidence package.

Govern model and supplier changes as custody changes

A model-provider switch is not a routine dependency upgrade when input handling, generated behavior, rights terms, regions, subprocessors, retention, security, or export changes. Require advance notice and buyer approval for material changes to:

  • model provider, family, version, checkpoint, adapter, or endpoint;
  • training, fine-tuning, retrieval, evaluation, or human-review service;
  • dataset, license, collector, labeling entity, or transformation;
  • system prompt, tool permissions, connector, memory, filter, or postprocessor;
  • account tier, retention, improvement use, human-access, privacy, or security settings;
  • work entity, contributor, country, city, device, or subcontractor;
  • repository, build, hosting, logging, backup, or monitoring boundary;
  • final decision owner or authorized-use policy; and
  • export format, service termination, support, or deletion capability.

For each change, identify affected ledger entries, rights, tests, security assumptions, human workflow, and recovery. Retest the minimum justified scope, record residual risk, and preserve the last accepted configuration. Do not let automatic provider upgrades erase reproducibility for a consequential workflow.

Monitor the whole system. Track output validity, groundedness, unsafe or prohibited content, security events, privacy leakage, retrieval authorization, latency, cost, model or data drift, human disagreement, override, correction, and downstream impact. Establish stop conditions and a non-AI or last-trusted path where the consequence requires it.

Retirement is a controlled change. Disable access, connectors, scheduled jobs, agents, service credentials, and write paths; preserve required decisions and evidence; export accepted artifacts and configurations; remove unauthorized copies; resolve customer and public records; document models and data that cannot be extracted; and test the replacement or manual process.

Compare international teams on proof, not regional labels

Nearshore and offshore teams can both serve Arkansas buyers. Geography changes overlap, travel, continuity, legal analysis, and operating rhythm; it does not prove rights discipline, security, AI competence, or accountability.

Require each bidder to demonstrate the same bounded slice and disclose:

  • contracting entity and every delivery, employer, agency, and subcontractor entity;
  • named people, roles, work cities, allocation, supervision, and replacement controls;
  • experience with the actual software, data, model, public-sector, or incident problem;
  • work assignment, direction, review, and acceptance process;
  • approved AI tools, accounts, input restrictions, generated-output review, and model-change controls;
  • contributor confidentiality and rights chain reviewed for the actual destination;
  • repositories, build, hosting, data, model, support, backup, and subprocessor locations;
  • secure-development, identity, device, logging, vulnerability, and incident evidence;
  • representative city-to-city overlap and urgent coverage;
  • continuity across staffing, network, power, provider, legal, and geopolitical disruption;
  • complete price and buyer-retained work; and
  • a tested export, identity revocation, replacement, and exit path.

Run a working session in which the team traces one input through directive, tool, output, evaluation, decision, release, incident, and exit. Give it an ambiguous data source and ask how it proves lawful use. Change the model version. Remove a contributor. Simulate a public-entity reviewer disagreeing with the score. Observe whether the provider asks good questions and preserves authority or rushes to a demo.

Check references only with permission and verify their scope. Do not publish a customer name or infer a relationship from a logo, marketplace review, employee résumé, or public project mention. Ask what the named team actually delivered, how custody was evidenced, what failed, and whether the customer could operate after exit.

Schedule from named cities and decisions

Most Arkansas locations use Central Time, but a useful delivery schedule names the buyer site and every contributor city using maintained IANA identifiers and representative dates. “Eight hours ahead” can change when countries transition daylight time on different dates or not at all.

Define separate windows for:

  1. Direction and design, when authorized people can resolve input, scope, rights, architecture, and acceptance questions.
  2. Asynchronous production, when a team can build or evaluate within documented boundaries without waiting for live approval.
  3. Human decision, when the authorized reviewer has the evidence, competence, time, and system access to decide.
  4. Release and recovery, when engineering, security, product, data, and rollback owners are present.
  5. Urgent incident response, with tested primary and backup contacts independent of the weekly meeting.

An asynchronous handoff should name the ledger ID, exact object, inputs used, work completed, tool/model/configuration, evidence links, test results, deviations, unresolved questions, prohibited next action, required decision, owner, and urgency. “Please approve” is not a decision packet.

Use IANA data to calculate overlap for dates that include seasonal transitions and holidays. Test the on-call path outside ordinary overlap. Do not purchase 24/7 coverage without staffing, response, authority, evidence, and recovery definitions.

Normalize complete cost

Compare proposals against the same custody and acceptance model. Use:

Complete cost = supplier fees + buyer direction and review + data and rights diligence + security and environments + model and tool usage + evaluation and rework + incident and retention operations + continuity + transition and exit.

Ask bidders to state:

  • named roles, levels, allocation, management, and review;
  • ordinary code, generated work, training, evaluation, documentation, and security included;
  • data collection, cleaning, labeling, licensing, synthetic generation, and rights work;
  • model, API, hosting, vector, observability, safety, and human-review fees at expected and stress volumes;
  • work cities, overlap, holidays, support, incident coverage, travel, and expenses;
  • currency, taxes, payment costs, rate changes, minimums, and termination fees;
  • buyer responsibilities for source materials, decisions, testing, public-entity approval, and production access;
  • included provenance, source, tests, evaluation, generated-output review, decision records, and release evidence;
  • vulnerability, model-change, incident, correction, and recovery support;
  • ownership, licenses, third-party restrictions, export formats, and continued-use costs; and
  • knowledge transfer, deletion, retention, replacement, and exit assistance.

Model ordinary delivery, increased inference volume, provider price change, model withdrawal, data challenge, rights dispute, security incident, supplier replacement, and a required five-year evidence retrieval. A low development rate can become expensive when the buyer must reconstruct inputs, repurchase data, re-evaluate a moving model, or keep the supplier because the runtime and decisions cannot be exported.

Run a paid input-to-exit pilot

Choose a bounded vertical slice with a meaningful generated artifact or recommendation but limited consequence. Four to six weeks is enough to test custody if the team keeps scope narrow.

Week 0: establish the boundary

  • Define outcome, objects, intended and prohibited uses, consequence, acceptance, and exit.
  • Name buyer, supplier, employer, contributor, model, data, system, and decision entities.
  • Review the Arkansas private, public-entity, state-agency, personal-information, and contract lanes that could apply.
  • Execute rights, confidentiality, data, security, tool, incident, continuity, and exit terms.
  • Create the direction-to-decision ledger and baseline costs.

Week 1: prove input and tool custody

  • Inventory buyer, supplier, and third-party inputs and lawful-use evidence.
  • Substitute synthetic or licensed material for uncertain inputs.
  • Establish buyer-owned repository, evidence index, identities, environments, logs, and secrets.
  • Lock approved model provider, account, version, region, retention, improvement, and connector settings.
  • Issue named contributor assignments and test an unauthorized-tool denial.

Weeks 2–3: produce and challenge the slice

  • Deliver a small working increment with exact input, directive, tool, output/model, source, tests, and limitations.
  • Evaluate against a baseline and representative valid, invalid, adversarial, conflicting, and out-of-scope inputs.
  • Review generated code or content for security, rights, factual, confidentiality, and quality defects.
  • Change one dataset or model setting through the approval route and prove lineage remains intact.
  • Reject at least one result and preserve why it was not accepted.

Week 4: human decision and incident exercise

  • Give the authorized reviewer enough context to accept, reject, override, or narrow use.
  • Record recommendation and final decision separately.
  • Simulate a supplier contributor attempting to approve the buyer’s decision or bypass a security control.
  • Inject suspected unauthorized acquisition from the prompt, training, or retrieval path; preserve evidence and relay facts immediately.
  • Draft a determination record without sending external notice.

Weeks 5–6: recovery and exit

  • Roll back the model or generated artifact to the last trusted state.
  • Export source, inputs, licenses, configuration, model artifacts available under the agreement, evaluations, decisions, logs, runbooks, and open risks.
  • Revoke a contributor and model-service identity.
  • Retrieve the incident determination and supporting record through the buyer’s retention path.
  • Have buyer or replacement personnel operate, review, change, and retire the slice without the supplier’s primary administrator.

Score input-lawfulness evidence, assignment clarity, direction trace, tool discipline, output quality, human-review quality, decision authority, security response, evidence retrieval, complete cost, communication, recovery, and exit independence. Expand only the work, data, tools, and authority supported by the evidence.

Minimum evidence before acceptance

  • Every material object is classified as buyer, supplier, third-party, human-created, generated, trained, recommended, decided, or incident evidence.
  • Important inputs have a source, lawful-use basis, permitted purpose, restrictions, and recheck owner.
  • The person and entity providing each material directive are identifiable.
  • Contributor employer, contract chain, assignment, scope, direction, tool use, and review are recorded.
  • The exact tool, model/version, account, region, retention, training/improvement, connector, and subprocessor boundary is approved.
  • The exact generated artifact or trained model is linked to inputs, direction, configuration, and evaluation.
  • Pre-existing buyer, supplier, and third-party rights and licenses remain separated.
  • Generated work has passed appropriate factual, security, rights, privacy, confidentiality, and quality review.
  • For covered public-entity work, the current authorized-use policy and authorized human final decision are evidenced.
  • State cybersecurity requirements are activated only for the exact covered systems and contract boundary.
  • Incident signals reach buyer owners immediately, while determinations and external communications remain separately authorized.
  • The Arkansas breach determination and supporting-document retention path can preserve and retrieve the record for five years when applicable.
  • Dated city-to-city overlap, urgent coverage, complete cost, continuity, and destination-specific diligence are visible.
  • Buyer or replacement personnel can export, operate, change, recover, and retire the accepted slice after supplier access is revoked.

If a material item is absent, reduce the inputs, tool permissions, consequence, audience, automation, or scope. Keep the output in draft, the model in evaluation, or the recommendation advisory until the buyer can prove custody and decision authority. Do not replace evidence with a generic assignment clause, a provider warranty, or a confident demo.

Frequently asked questions

Can an Arkansas company hire an overseas software or AI team?

Potentially. The answer depends on the work, data, systems, contributor countries, contracts, rights, security, customer and sector duties, sanctions and export questions, tax and employment issues, and the intended use. Start with a bounded work package, lawfully sourced inputs, named contributors, buyer-owned systems, measurable acceptance, and tested exit. Obtain qualified advice where the facts require it.

What is a direction-to-decision custody ledger?

It is a buyer-owned record connecting one material artifact, trained model, recommendation, or decision to its purpose, input sources, operative directive, contributor and entity, AI tool and configuration, exact result, evaluation, authorized human decision, security and incident evidence, and exit package. It makes silent substitutions and unclear ownership claims easier to detect.

Does Arkansas Act 927 guarantee that every AI output belongs to the person who typed the prompt?

No blanket conclusion is safe. The enacted text includes conditions and separate treatment involving inputs or directives, training data, lawful acquisition, contractual transfer, employee scope, employer direction and control, and pre-existing copyright or other intellectual-property rights. Apply the current text to the actual facts with qualified advice; preserve evidence instead of relying on a slogan.

If an overseas supplier’s employee uses AI, does the Arkansas buyer automatically own the result?

Do not assume that. Identify the contributor’s employer, assignment, scope, direction and control, supplier agreement, flow-down terms, AI provider terms, pre-existing materials, destination law, and buyer acceptance. The buyer’s contract and operational evidence should address each material object and the entire entity chain.

Is a prompt history enough to prove ownership or quality?

No. A prompt history may help show direction, but it does not prove that inputs were lawfully acquired, the contributor acted for the expected entity, third-party rights are clear, the result is original or accurate, code is secure, a model is reproducible, or the buyer accepted the object. The ledger joins those separate facts.

Must an Arkansas public entity let a human make the final decision?

Act 848 requires covered public entities to create authorized-use policies and requires an authorized human employee or designee to make any final decision in the course of employment regardless of the tool’s recommendation. The entity’s current policy and the precise use control implementation. The supplier should preserve recommendation evidence and support meaningful review without taking over the public entity’s final authority.

Can the overseas provider be the “human in the loop” for a public entity?

Do not treat an unidentified provider reviewer as sufficient. Confirm the entity’s policy, the definition and authorization of the employee or designee, procurement and delegation terms, and accountability for the particular decision. A supplier can support, explain, test, or administer while the named authorized person retains the final action.

Does every Arkansas buyer have to follow State Cybersecurity Office standards?

No. Act 489 concerns the State Cybersecurity Office and state-agency cybersecurity and information-security functions. Private buyers should not present state-agency controls as universally mandatory. For actual state work, identify the current policies, standards, data classification, agency terms, and contract clauses that apply to the exact system.

What should an overseas supplier do after finding a possible personal-information breach?

Preserve evidence, contain within authority, and notify the buyer promptly with staged facts. Arkansas law includes an immediate maintainer-to-owner or licensee path under stated conditions. The buyer’s accountable owners should determine applicability, affected people, notices, Attorney General reporting, communication, and retention with qualified advice; the provider should not delay the first signal until its investigation is complete.

Why retain a breach determination for five years?

Arkansas’s enacted amendments require a person or business to retain the written breach determination and supporting documentation for five years and provide a defined Attorney General request path. The operating system should therefore produce a retrievable, access-controlled determination whether notice is required or not, while reconciling other retention and legal-hold duties.

Is nearshore better than offshore for an Arkansas AI project?

Not universally. Nearshore teams may provide longer live overlap; offshore teams may offer specialized expertise or useful asynchronous work. Compare named entities and people on input provenance, AI-tool discipline, direction, evaluation, security, decision support, exact city-to-city overlap, complete cost, continuity, and tested exit—not a regional stereotype.

What is the best first outsourced project for an Arkansas buyer?

Choose a bounded vertical slice with real value, minimized or synthetic data, an approved model/tool, a buyer-owned repository, measurable acceptance, and no autonomous consequential action. Require input provenance, an exact directive and output, human evaluation, a rejected case, a model-change test, an incident drill, recovery, contributor revocation, and complete handover before expanding scope.

Next step

Use the project brief generator to define the outcome, then add the object inventory, input provenance, directive and entity chain, contributor assignments, approved AI tools and settings, evaluation plan, human decision authority, public-entity or state controls where applicable, incident and five-year determination-retention path, complete-cost assumptions, and exit test. Score proposed teams with the provider scorecard and require a paid input-to-exit pilot before expanding data, automation, or decision authority.

Evidence ledger

Sources used on this page

  1. Arkansas Act 927 of 2025 — Generative artificial intelligence tool ownership — Arkansas General Assembly. Supports: Official enacted text for Arkansas Code § 18-4-101 concerning the person providing an input or directive, lawful acquisition of training data, contractual transfer, employer-directed work within scope and under employer control, and the express limitation for pre-existing copyright and intellectual-property rights. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  2. Arkansas Act 848 of 2025 — Authorized use of artificial intelligence by public entities — Arkansas General Assembly. Supports: Official enacted text amending Arkansas Code § 25-1-128 to require covered public entities to define authorized AI and automated-decision-tool use, retain an authorized human employee or designee for final decisions, train employees, and prohibit intentional avoidance of security and system-integrity procedures. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  3. Arkansas Act 489 of 2025 — Arkansas Cybersecurity Act — Arkansas General Assembly. Supports: Official enacted text establishing State Cybersecurity Office responsibilities for state-agency cybersecurity and information security, including governance, data classification, design controls, breach notification, monitoring, assessment, remediation, training, auditing, incident response, and recovery. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  4. Arkansas Act 1030 of 2019 — Personal Information Protection Act amendments — Arkansas General Assembly. Supports: Official enacted amendments addressing biometric data, immediate maintainer-to-owner or licensee breach escalation, Attorney General reporting for events affecting more than 1,000 individuals under the stated conditions, and five-year retention of the written breach determination and supporting documentation. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  5. Artificial Intelligence Risk Management Framework — National Institute of Standards and Technology. Supports: Maintained federal methodology for governing, mapping, measuring, and managing AI risks across design, development, deployment, use, evaluation, and retirement. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  6. NIST AI 600-1 — Generative Artificial Intelligence Profile — National Institute of Standards and Technology. Supports: Cross-sector federal methodology for risks and actions specific to generative AI, including governance, data and model provenance, content risks, evaluation, security, human oversight, supplier dependencies, monitoring, and incident handling. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  7. Secure Software Development Framework — National Institute of Standards and Technology. Supports: Maintained secure-development methodology for organizational preparation, protected software and environments, well-secured releases, provenance, vulnerability response, and evidence shared between producers and acquirers. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  8. NIST SP 800-61 Rev. 3 — Incident Response Recommendations and Considerations — National Institute of Standards and Technology. Supports: Current final incident-response methodology for integrating preparation, detection, response, recovery, improvement, and cybersecurity risk management. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  9. IANA Time Zone Database — Internet Assigned Numbers Authority. Supports: Maintained time-zone identifiers and transition rules for calculating dated overlap between Arkansas buyer locations and proposed international delivery cities. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  10. Directory of Intellectual Property Offices — World Intellectual Property Organization. Supports: Official destination-country intellectual-property office links for researching contributor, copyright, software, invention, design, model, and rights-chain questions without assuming one Arkansas clause resolves every jurisdiction. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.

Next scheduled review: October 15, 2026. Corrections: hello@outsourcing.ai.