Kansas buyer guide

Outsourcing software development from Kansas

A Kansas buyer guide to international software and AI: positive-control data, model and component provenance, human release, incidents, records, cost, and exit.

For: Kansas founders, product and engineering leaders, State entities and contractors, medical and research facilities, security and privacy teams, data owners, procurement owners, records custodians, and operations leaders evaluating software, automation, data, or AI delivery outside the United StatesBy Outsourcing.ai Editorial Team
The decisionA Kansas buyer should issue an origin-and-authority circuit breaker before an international team uses AI or touches a controlled work package. Separate ordinary private delivery from covered State work and the narrower genetic-technology perimeter; classify every input; prove model, platform, component, producer, controller, and subprocessor provenance; activate all six positive-control conditions before sensitive State information enters AI; constrain agentic authority; keep prohibited platforms and origin-linked genetic technology disconnected; preserve human release, annotated code, accessible acceptance, incident facts, records, and a tested exit.Evidence references: [1][2][3][4][5][6][7][8][9][10][11][12][13][14][15][16]
Three abstract data classes and four AI autonomy nodes feeding a six-ring positive-control chamber, with component genealogy, two separate statutory disconnects, an eligible-artifact bridge, mechanical human-release aperture, records, rollback, exit, and emergency-stop paths
A Kansas origin-and-authority circuit breaker classifies inputs, proves model and component genealogy, activates six sensitive-data controls, keeps two narrow statutory disconnects separate, and lets only a provenance-cleared artifact reach human release, records, recovery, and portable exit. Original Outsourcing.ai editorial illustration, generated with AI and reviewed for relevance and accuracy.
No local-office claim. Outsourcing.ai is an online research and delivery platform. This guide is for Kansas-based buyers; it does not represent a Kansas office, local staff, completed Kansas client work, State approval, government-contractor status, procurement eligibility, AI authorization, medical or research eligibility, cybersecurity approval, accessibility certification, or legal, privacy, security, health, employment, tax, financial, export-control, procurement, or intellectual-property advice.
Direct answerA Kansas buyer can use an international software or AI team when access follows the work's actual perimeter and every consequential action remains reversible. Build an origin-and-authority circuit breaker for one versioned work package. Separate ordinary private delivery from covered State work and from the narrower genetic-analysis technology rule. Classify inputs and systems; an unclassified State item defaults to Restricted. For covered State AI, document whether use is internal, external, agentic, or autonomous; satisfy all six positive-control conditions before sensitive input; disclose AI integrations; prove model-training rights, prompt/output handling, human intervention, code review, inventory, and disablement. Disconnect prohibited platforms from State devices and networks. For covered genetic-analysis facilities, prove producer, domicile, ownership, control, subsidiary, device, and software origin before use. Keep the private breach, State incident, records, accessibility, release, and exit branches separately owned.

Kansas outsourcing at a glance

Proposed workDefault circuit laneEvidence before access or release
Ordinary private application, integration, infrastructure, or test workBuyer-defined engineering laneReal contracting entity and people, scope, architecture, repositories, environments, data, dependencies, secure-development proof, acceptance, complete cost, incident relay, and exit
Internal State AI using non-sensitive informationControlled internal-use laneUse case and owner, input/output retention and training setting, human review, source validation, inventory, approved access, model/version, logs, risk treatment, and renewal date
Public-facing or decision-influencing State AIExternal-accountability laneDefined guardrails, knowledgeable human accountability, timely intervention, uncertainty escalation, perceptible attribution, monitoring, appeal or correction, accessibility, and release approval
Sensitive State information in AISix-condition positive-control chamberNo provider retention/training, permission before dissemination, deletion ability, entity-accessible interaction logs, no runtime retraining without authority, ephemeral external-user input, classification owner, and contract attestation
Agentic or autonomous State AIBounded-authority and circuit-breaker laneExplicit objective, allowed tools/actions, credential and spend limits, human gates, traces, anomaly controls, suspension/disable test, inventory, training, annual review, and material-capability trigger
AI platform of concern on a State device or networkStatutory disconnect laneCurrent platform ownership/control determination, blocked access, account deactivation/deletion, network enforcement, exception authority if applicable, and proof that substitutes and embedded features do not reconnect it
Genetic-analysis technology in a covered Kansas facilityOrigin/provenance stop laneFacility applicability, device and software functions, producer/domicile/ownership/control/subsidiary evidence, removal or permanent disablement where required, approved replacement, data migration, validation, and record
External-facing or Restricted-Use State softwareSecure-release laneThreat model, dependency and SBOM evidence, SAST/DAST/composition results, flaw remediation, annotated AI-generated code, human acceptance, deployment authorization, monitoring, rollback, and documentation
Covered personal-information eventImmediate factual relay with owner and maintainer branchesDiscovery and acquisition facts, role, affected fields and Kansas residents, misuse investigation, containment, preservation, owner notice, consumer decision, reporting-agency threshold, recovery, and updates
State ICT or public record in a supplier platformAccessibility-and-custody laneWCAG/Section 508/Title II evidence, ACR where required, exception and alternative-means path, record owner, searchable export, printable form, retention schedule, permanent access/change/delete history where applicable, and tested exit

The lanes are not interchangeable. A lawful international team is not proof that every model or component is eligible. A permitted model is not permission to expose sensitive data. A security scan is not human authorization for public decisions. A private business is not governed by every Executive Branch control. The circuit breaker holds those distinctions through procurement, delivery, incident response, and exit.

The core decision: can the buyer prove origin and authority at runtime?

Most outsourcing questionnaires ask where people sit. Kansas now makes a more precise question useful: what technology is acting, who or what controls it, what data enters it, and who can stop it? The answer can change after contract signature because a supplier adds an embedded assistant, changes a model endpoint, replaces a subprocessor, introduces an agent, or upgrades a component.

Create a versioned circuit record for each release, automation, or AI use case. It should contain:

  1. Purpose and prohibited adjacency. State the permitted outcome, user, decision, data, environment, and excluded uses. “Improve support” is not enough; define whether the system drafts, recommends, communicates, changes records, issues refunds, or affects a public service.
  2. Applicability branch. Record ordinary private work, covered Executive Branch work, another public-body contract, State device/network use, covered medical or research facility use, or a combination. Cite the executed instrument or owner determination rather than inferring scope from a Kansas address.
  3. Technology genealogy. Identify model, platform, host, API, application, embedded AI, open-source components, binaries, devices, operational software, producer, domicile, direct and indirect control, parents, subsidiaries, successors, regions, and subprocessors.
  4. Information class and lineage. List each source, owner, Public/Private/Restricted class for covered State data, contractual restrictions, derived data, prompt and retrieval path, logs, evaluation sets, copies, backups, and disposal. Treat unclassified State information and systems as Restricted until classified.
  5. AI operating class. Mark internal or external/customer-facing, assistive, conversational/generative, agentic, or autonomous decision-support. Record actual tool and action access rather than the vendor’s marketing label.
  6. Positive-control proof. For sensitive State AI input, verify every condition: no retention/training, no dissemination without permission, deletion capability, entity-accessible logs, no runtime retraining without authority, and automatic deletion of external-user inputs after the intended function.
  7. Human authority. Name who approves data use, model use, public attribution, source conclusions, rights, accessibility, deployment, transactions, incidents, records, recovery, and exit. Define intervention time and a real suspension mechanism.
  8. Code and supply-chain evidence. Preserve source provenance, AI-generated-code annotations, dependency lock, SBOM, licenses, build attestation, SAST, DAST, composition analysis, test results, remediation, release identity, and rollback artifact.
  9. Records and observability. Define prompt/output/event logging, protected log fields, record custody, search and export, printable production, retention schedule, legal hold, access/change/delete history, monitoring, anomaly detection, and correction evidence.
  10. People and time. Name each entity, contributor, supervisor, city, approved device, work schedule, replacement process, and escalation owner. Use the Kansas buyer’s actual IANA zone, not a statewide assumption.
  11. Change tripwires. Reopen review for a new model, owner, controller, embedded feature, autonomy level, tool, action, data class, training behavior, retention term, subprocessor, producer, facility, purpose, public audience, country, incident, or material capability.
  12. Exit and removal. Prove code, data, records, prompts, evaluations, inventories, licenses, configuration, accounts, access, deletion, permanent disablement where required, replacement validation, runbooks, and operation by a replacement team.

Attach the circuit ID to the statement of work, access group, AI inventory entry, repository release, model configuration, device/software inventory, approval, incident record, invoice, and exit certificate. The international supplier can produce evidence. It should not be able to redefine applicability, self-approve sensitive input, choose its own exception, or release a consequential system because a task is complete.

Start with the current Kansas AI operating classes

Kansas ITEC 6200-P, effective May 19, 2026, supersedes the earlier OITS generative-AI policy. It applies to Executive Branch entities and defines entity to include agents and contractors acting on their behalf. It does not merely govern chat prompts. It covers embedded AI and distinguishes internal use from systems that interact with the public or influence public services, eligibility, rights, enforcement, or regulatory action.

Operating classWhat changes for the work packageMinimum control proof
Internal AISupports employees or contractors without directly interacting with or determining outcomes for the publicApproved purpose; input/output setting; knowledgeable human review or justified monitoring; no sole-source decisions; no unsupported official position; access, inventory, and renewal
External/customer-facing AIInteracts with the public or informs, influences, or automates consequential public operationsGuardrails; designated human accountability; timely intervention; uncertainty recognition and escalation; platform monitoring or equivalent controls; perceptible attribution; correction and appeal path
Agentic AIPursues goals, calls tools, interacts with systems, or takes actions with limited ongoing inputExplicit scope of authority; credential, tool, action, environment, transaction, spend, and volume limits; trace; human gate; anomaly detection; suspend/restrict/disable control
Autonomous decision-supportOperates at the highest end of the policy’s autonomy spectrumDefault high scrutiny; no sole reliance for final decisions; human authority and intervention; affected-person safeguards; continuous monitoring; narrow release; tested fallback and disablement

Do not classify by interface. A chatbot that only searches approved public guidance may be external but low authority. A background service with no conversational interface can be agentic if it selects tools, changes data, or initiates transactions. An IDE completion tool can create supply-chain and confidentiality exposure even if it never reaches the public.

For every use case, draw an authority graph: observe, retrieve, draft, classify, recommend, write, execute, communicate, decide, spend, delete, and change configuration. Give the system only the nodes it needs. Require a named human or deterministic policy gate before a consequential edge. The graph is both a design artifact and an acceptance test.

Put sensitive inputs inside a six-condition chamber

The current Kansas policy permits sensitive AI input only when all of section 7.1.1’s conditions are met. Sensitive includes material inappropriate for public release, Restricted-Use Information, contractually or legally confidential data, and entity-classified sensitive data. The controls are conjunctive: five out of six is a failed chamber.

Required conditionContract and technical evidenceFailure response
Input and output are not retained or used for trainingProvider term and signed attestation; tenant setting; API configuration; network trace or admin evidence; subprocessor flow; test accountBlock the data path; use public/synthetic fixtures; obtain authorized compliant service or redesign
Input/output is not disseminated without appointing-authority permissionRole and approval workflow; publication control; export restriction; downstream connector allowlistStop release and connector actions; preserve attempted event; route to authority
Input and output can be deleted or removedDeletion API and admin workflow; backup/subprocessor coverage; test evidence; residual-data statementDo not approve the sensitive path without a documented exception or different architecture
Interactions are logged and logs are accessible to the entityEvent schema; prompt/output or protected reference; actor, model, version, tools, actions, time, result; entity export and search testDisable or constrain use until decision evidence can be reconstructed
Runtime interactions do not retrain or modify models without explicit authorityTraining/off switch; model immutability; version pin; change alert; appointing-authority approval fieldFreeze model/version, reject silent learning, and reopen the circuit on change
External-user inputs are used only for the intended function and automatically deleted on completionPurpose binding; ephemeral storage design; deletion event; session test; exception handling; telemetry minimizationBlock public release or route input to a non-AI deterministic service

“Enterprise” is not evidence. A provider can offer a business plan while retaining abuse-monitoring copies, sending content to a subprocessor, keeping logs outside the buyer’s access, or changing model-training terms. Test the exact SKU, tenant, region, endpoint, configuration, and contract used by the project.

Positive control also means knowing where data does not go. Diagram prompt construction, retrieval, embeddings, evaluation, moderation, caching, tracing, analytics, support, backups, and deletion. Apply the highest relevant class to derived prompts, summaries, vectors, and logs until the owner documents a defensible reduction. Minimize at the boundary rather than promising to delete an unnecessary copy later.

Build a provenance gate for model, platform, component, and producer

Kansas section 75-4720 and section 65-449 create two different technology-origin controls. They should not be collapsed into a nationality ban on people or vendors.

The State-device/network rule applies to an AI platform of concern as defined by current law. It blocks access from State-owned or State-issued employee devices, requires State-operated networks to prohibit access, and requires State agencies to deactivate and delete affected accounts. It includes a narrow exception for law-enforcement activity or cybersecurity investigation. An ordinary private Kansas company is not automatically placed inside that State-device rule.

The genetic-technology rule is separately scoped to medical or research facilities receiving State money and conducting covered genetic work. It reaches genetic sequencers and operational or research software used for genetic analysis produced in or by defined foreign-adversary, state-owned, domiciled, subsidiary, or controlled sources. It requires prohibited technology that is not permanently disabled to be removed and replaced. This is broader than checking the brand printed on a device and narrower than treating every health application or every international contributor as prohibited.

Use a provenance matrix for each relevant technology:

  • exact product, model, binary, device, firmware, service, API, and version;
  • stated producer and software publisher;
  • corporate domicile and operating entity;
  • direct and indirect ownership and control;
  • parent, subsidiary, successor, reseller, OEM, white-label, and hosting relationships;
  • model owner/controller and endpoint actually called;
  • embedded assistants, transitive services, telemetry, update channels, and fallback endpoints;
  • source of genetic-analysis operational or research software where that narrow facility rule applies;
  • signed supplier statement, independent registry evidence, contractual change notice, and recheck date;
  • block, deactivate, delete, permanently disable, remove, replace, migrate, validate, and dispose actions where required.

Treat unknown origin as unresolved, not approved. A software bill of materials helps with libraries; it does not alone establish model control, corporate relationships, device provenance, data-processing subprocessors, or a hosted endpoint’s silent fallback. Add a model/service bill and a control-chain declaration.

The goal is a clean circuit, not geopolitical theater. A qualified contributor working from a permissible country can still introduce a prohibited platform. A U.S. reseller can still wrap an ineligible underlying component. Conversely, an international delivery company should not be rejected solely because its team is outside the United States when its people, tools, components, data path, and authority all satisfy the actual perimeter.

Constrain agentic authority before testing output quality

Agentic systems create risk through actions, not only incorrect text. A provider demo may show a good answer while hiding broad credentials, recursive tool calls, silent retries, uncontrolled spend, destructive actions, or a failure to stop.

For each agent or automated process, issue a capability lease:

  • one objective and an explicit list of prohibited adjacent objectives;
  • approved model and model version;
  • allowed data classes, repositories, records, and retrieval scopes;
  • allowed tools, APIs, functions, commands, domains, queues, and environments;
  • read, propose, write, transact, communicate, delete, and configuration permissions;
  • maximum duration, calls, tokens, dollars, records, recipients, and concurrent actions;
  • required human confirmation points and maximum intervention time;
  • trace fields sufficient to reproduce decisions without overexposing sensitive content;
  • anomaly thresholds, circuit-open behavior, queued-action cancellation, credential revocation, and safe fallback;
  • expiry, renewal owner, material-capability trigger, and exit deletion.

Test the stop path before production. Revoke a credential while a run is active. Trigger the volume ceiling. Simulate an unavailable human. Inject an instruction from an untrusted document. Change the model response format. Confirm that queued actions halt and that the buyer can reconstruct what executed, what did not, and what state needs reconciliation.

Kansas policy requires the ability to suspend, restrict, or disable AI systems when risk exceeds acceptable thresholds. A dashboard toggle that does not revoke tool credentials, terminate workers, stop queued work, disable callbacks, or block alternate endpoints is not a circuit breaker. Document the complete disable graph and measure it during the pilot.

Turn AI-generated code into an inspectable release

Kansas requires all AI-generated code to be annotated and permits implementation only after business and security risks are identified and mitigated. Code that processes sensitive data, executes unattended, connects to external services, or performs transactional or system actions must receive qualified human review or appropriate application testing. The secure-development policy separately covers software for Restricted-Use Information systems or external-facing systems, including third-party vendor work.

Make the release packet prove:

  1. repository, commit, branch protection, reviewer, and accepted artifact identity;
  2. which files or units contain AI-generated or materially AI-assisted code and which tool/model produced it;
  3. prompt and source handling compatible with confidentiality and rights requirements;
  4. dependency lock, SBOM, component origin, licenses, known vulnerabilities, and update ownership;
  5. threat model and abuse cases for public, sensitive, unattended, external-service, transactional, and agentic behavior;
  6. SAST, DAST, software-composition, secret, infrastructure, API, authorization, and manual review evidence appropriate to the system;
  7. tests covering happy paths, boundary cases, denial, concurrency, idempotency, retry, rate limits, injection, data leakage, rollback, and disablement;
  8. resolved findings, accepted residual risks, named owner, expiry, and re-test trigger;
  9. reproducible build, configuration, deployment approval, monitoring, rollback artifact, and recovery procedure;
  10. source, documentation, credentials, accounts, infrastructure, data migration, and replacement-team exit.

Annotation should be useful, not decorative. A blanket comment saying “AI may have helped” cannot support risk review or future maintenance. Store structured provenance near the pull request or release manifest: tool/model, date, contributor, affected scope, review performed, test evidence, rights conclusion, and approval. Avoid publishing sensitive prompts into the repository.

Independent review matters most when the person who accepted the generated output is the same person who prompted it. Use a second qualified reviewer for authentication, authorization, cryptography, money movement, public decisions, health or safety paths, data deletion, infrastructure changes, and agentic tool execution.

Preserve human accountability and visible public attribution

For external State AI, the policy requires guardrails, designated human accountability, timely intervention, uncertainty escalation, and perceptible attribution for substantially AI-generated public-facing or official communication. That creates an acceptance surface beyond model accuracy.

Define the human release role for each outcome:

  • source owner validates authoritative input and update cadence;
  • domain reviewer assesses accuracy, neutrality, completeness, and limitations;
  • data owner approves class, purpose, minimization, retention, and deletion;
  • security owner approves threat treatment, access, monitoring, disablement, and recovery;
  • accessibility owner accepts the complete user path and alternative means;
  • service owner approves public guardrails, escalation, attribution, correction, and appeal;
  • release owner binds the reviewed evidence to one deployable version;
  • incident owner decides characterization, notification, recovery, and external communication.

Do not reduce intervention to a “contact us” link. State maximum response time, operating hours, after-hours behavior, what the AI does while waiting, which action is reversible, and how a person corrects the source and every derived state. For a consequential service, test a disputed output and confirm that the system preserves the original event, routes it to the right owner, prevents repeat harm, and communicates the corrected result.

Attribution should be visible and understandable at the point where AI materially shapes the communication. It should not imply that an automated response is an official determination or that a State employee reviewed a specific result when only periodic monitoring occurred. Pair attribution with limitation, human route, and correction mechanism.

Keep public records outside the supplier’s memory

Kansas government records can span documents, reports, maps, recordings, and other data or information regardless of form, storage medium, or condition of use. Disposal follows law and approved retention schedules. For required records maintained only on electronically accessed media, section 45-501 requires preservation, examination, ready use, printable production, security procedures, and a permanent record of people who access, amend, or delete the record.

An AI transcript, prompt, retrieved source, decision trace, access event, generated artifact, review, correction, or deletion event may become relevant to a record determination depending on purpose and custody. The supplier should preserve capabilities; the designated custodian and counsel decide treatment.

Before access, test the records path:

  1. create a representative prompt, tool trace, generated output, human review, correction, and approval;
  2. export it in a documented, non-proprietary or usable format with stable identifiers and timestamps;
  3. search by matter, actor, model, release, date, source, and outcome without revealing unrelated protected records;
  4. produce a readable and printable form with attachments, provenance, and redaction support;
  5. preserve access, amendment, and deletion history where the statutory electronic-media condition applies;
  6. apply the designated retention schedule and hold without relying on the vendor’s default chat history;
  7. migrate the record to a buyer-controlled repository and prove completeness;
  8. delete eligible supplier copies and verify the remaining backup/subprocessor state.

Do not retain every raw prompt forever “just in case.” That increases exposure and can conflict with minimization and approved schedules. Keep decision-sufficient evidence under an owner-approved class and retention rule. Use protected references or hashes when full sensitive content is not necessary for the audit purpose.

Build separate private-breach and State-incident branches

Kansas sections 50-7a01 and 50-7a02 create a focused personal-information breach path. The owner or licensee conducts a prompt, good-faith misuse investigation and, when misuse occurred or is reasonably likely, notifies affected Kansas residents as soon as possible and without unreasonable delay, subject to law-enforcement and restoration constraints. A maintainer that does not own or license the data notifies the owner or licensee after discovering covered unauthorized access and acquisition. A notice event affecting more than 1,000 consumers at one time adds notice to nationwide consumer-reporting agencies; it is not a general Attorney General notice threshold.

That chapter’s personal-information and breach definitions are specific. Do not label every security event a statutory breach, and do not let a supplier delay the factual relay while it tries to make the legal decision. The buyer may need facts for contract, State policy, sector rules, insurance, law enforcement, customers, or another jurisdiction even when Kansas section 50-7a02 does not activate.

The incident card should capture:

  • first observed time, discovery time, system, environment, reporter, and current status;
  • unauthorized access and acquisition facts, not only alert labels;
  • affected data elements, encryption/redaction state, identities, Kansas-resident estimate, and other jurisdictions;
  • owner/licensee, maintainer, State entity, service provider, and subprocessor roles;
  • affected model, prompt store, retrieval index, agent trace, code, dependency, account, device, or network;
  • suspected misuse, evidence basis, missing facts, and investigation owner;
  • containment already taken, actions requiring buyer approval, and risk of evidence loss;
  • provider and subprocessor notifications, law-enforcement hold, consumer-reporting threshold, and other applicable lanes;
  • recovery, credential rotation, model or component removal, data correction, queued-action reconciliation, monitoring, and update cadence.

Use an immediate contract relay measured in minutes or hours, followed by progressive updates. “Without unreasonable delay” is an external outcome, not a useful supplier response target. Preserve the buyer’s authority over legal characterization, residents, regulators, public statements, restoration, and closure.

Make accessibility a release artifact

Current Kansas ITEC 1210-P applies to Executive Branch ICT that is procured, developed, maintained, used, or provided through contractual or licensing arrangements. It incorporates Revised Section 508, ADA Title II Subpart H, and WCAG 2.1 A and AA. The KARS project materials call for an Accessibility Conformance Report produced using the VPAT format. A documented best-meets exception requires market research, identified unmet provisions, alternative means, and State ADA Coordinator approval before deployment.

For an international delivery team, put accessibility in acceptance:

  • semantic structure, headings, names, roles, states, values, instructions, and errors;
  • keyboard operation, visible focus, logical focus order, modal and menu behavior, and no traps;
  • text zoom, reflow, orientation, spacing, contrast, non-color cues, target size, and responsive tables;
  • form labels, validation, status messages, timing, authentication, and recovery;
  • captions, transcripts, audio description where applicable, reduced motion, and flashing limits;
  • screen-reader checks with representative browser/assistive-technology combinations;
  • mobile web or native-app paths, documents, PDFs, email, downloadable artifacts, and third-party widgets;
  • ACR claims linked to observed evidence, known gaps, remediation owner, release ID, and regression suite;
  • alternative means tested by users before any approved exception relies on it.

An automated scan is evidence, not acceptance. It will miss incorrect reading order, misleading labels, unusable error recovery, inaccessible generated documents, and a chatbot that traps a user in an automated path. Test the complete task with the AI attribution and human-intervention route included.

Use the real Kansas clock and an explicit handoff envelope

Most Kansas buyers operate on Central time, while the federal boundary places a western Kansas area in Mountain time. The operational lesson is not to memorize a state label. Record the buyer’s actual site and maintained IANA identifier, then calculate overlap for the dated pilot because daylight transitions differ across countries.

Define three windows:

  • decision window: the named buyer owner is available for data, access, public-service, transaction, incident, and release decisions;
  • collaboration window: buyer and supplier can pair, review, clarify, and demonstrate work;
  • autonomous window: only pre-approved, observable, reversible tasks may run without immediate overlap.

If a buyer in Goodland and a buyer in Wichita use the same supplier schedule without an explicit zone, one will inherit a hidden one-hour difference. Store timestamps in UTC, show the local zone and offset in human interfaces, and never abbreviate a deadline as “CT” or “MT” in a contract without a named location or IANA zone.

A handoff envelope should state accepted work, rejected work, unresolved questions, data class, release identity, active agents/jobs, queued actions, incidents, evidence links, required human decisions, next owner, and expiration. The supplier cannot turn lack of overlap into permission to deploy, notify, spend, delete, or expand scope.

Select a provider by proof, not by geography

Score the real entity and proposed team. A polished U.S. sales organization can hide an unreviewed subprocessor or model endpoint. A transparent international team can offer stronger origin, access, testing, and exit proof.

Selection areaStrong evidenceWarning sign
Entity and peopleLegal entity, contributor identities and locations, employment/subcontract chain, screening appropriate to access, stable supervisors, replacement approvalMarketplace profile or brand only; anonymous bench; silent substitutions
AI and component provenanceModel/service inventory, corporate control and subprocessor chain, SBOM, signed non-retention/training terms, embedded-feature scan, change notification“We use approved AI” without endpoint, owner, version, terms, or component genealogy
Positive controlDemonstrated six-condition chamber, entity-accessible logs, deletion, permission gate, human intervention, disablementEnterprise-plan screenshot; logs only visible to supplier; no complete stop test
Secure deliveryProtected repositories, least privilege, approved remote access, reproducible build, code annotations, SAST/DAST/composition evidence, remediationShared credentials, production-first testing, unverifiable AI code, reports from another product
Rights and training dataContributor assignment, third-party license register, model-training diligence, prompt/source rule, destination-law reviewBlanket “work for hire everywhere,” scraped-data assurance without evidence, undisclosed model use
AccessibilityRelease-specific ACR and tests, known gaps, assistive-technology evidence, regression, alternative meansGeneric compliance badge or scanner score only
Incidents and recordsImmediate factual relay, progressive update template, export/search/print test, retention and hold support, access/change/delete historySupplier alone decides if an event matters; records trapped in chat or ticket UI
ExitBuyer-controlled source and accounts, infrastructure and configuration, data/record export, credential revocation, deletion, replacement-team rehearsalExport discussed after termination; proprietary build path; no component or model inventory

Verify evidence in a paid pilot. Do not ask for sensitive customer reports or other clients’ confidential penetration tests. A provider can demonstrate the mechanism with buyer-owned fixtures and a scoped environment.

Compare complete cost and downside

Hourly rate matters, but Kansas-specific control work changes the cost surface. Compare the same accepted outcome over the same period.

Complete cost = supplier delivery + buyer-retained work + control evidence + platform and infrastructure + transition and overlap + risk reserve + exit.

Supplier delivery includes discovery, design, engineering, data, model work, testing, documentation, management, and warranty. Buyer-retained work includes product decisions, classification, applicability, appointing authority, security, accessibility, records, incident, release, and acceptance. Control evidence includes provenance research, AI inventory, provider attestations, code annotation, SBOM, evaluation, logging, accessibility evidence, and circuit-breaker drills. Transition includes knowledge transfer, clock handoff, replacement validation, and parallel operation. Risk reserve prices a realistic scenario such as a provider changing model terms, an embedded AI endpoint failing provenance, a component vulnerability, inaccessible release, or an incident requiring reconstruction.

Normalize proposals with the same work-breakdown structure:

  • deliverables and excluded work;
  • role, seniority, location, allocation, rate, and replacement assumptions;
  • model, platform, component, license, hosting, logging, security, and accessibility costs;
  • buyer review and authority hours;
  • remediation, regression, incident, recovery, documentation, and handover;
  • currency, tax, fee, inflation, minimum, overtime, and termination assumptions;
  • confidence range, dependencies, evidence gaps, and reserve.

A low quote that excludes provenance, sensitive-data controls, agent disablement, accessibility, incident evidence, records export, and exit is not comparable. It transfers cost into buyer labor and downside.

Run an origin-and-authority pilot

A useful pilot proves one narrow vertical slice and the controls around it. A six-week example could be:

Week 1 — applicability and genealogy. Choose one bounded use case. Record private/State/facility branches, data classes, AI class, model and component genealogy, people, places, roles, rights, and excluded uses. Reject unresolved prohibited paths.

Week 2 — positive-control chamber. Configure retention/training, deletion, logging, permission, runtime-learning, and external-input behavior. Use synthetic or public fixtures first. Demonstrate each condition and capture the exact tenant/version evidence.

Week 3 — bounded build. Implement one end-to-end path with least privilege, AI-code annotations, dependency lock, SBOM, secure tests, public attribution if applicable, and buyer-controlled source/build infrastructure.

Week 4 — failure and intervention. Test uncertainty, bad source, prompt injection, unauthorized tool, spending/volume limit, provider outage, model change, inaccessible response, credential revocation, queued-action cancellation, rollback, and complete disablement.

Week 5 — records, incident, and accessibility. Export/search/print a representative record and access/change/delete history; exercise the maintainer-to-owner incident card; complete keyboard, screen-reader, zoom/reflow, and document checks; remediate findings.

Week 6 — release and exit. Bind evidence to one release. Have a buyer reviewer reproduce the build, operate the service, open the circuit, restore it safely, export records, rotate credentials, and hand the package to a person who did not build it.

Pilot pass conditions should be binary where possible: every sensitive-data condition proven; no unresolved technology-origin path; prohibited endpoint inaccessible from the scoped State environment; every consequential action bounded; disablement stops all execution paths; release reproducible; critical findings resolved; accessibility task completed; record export complete; incident relay timely; replacement operator succeeds.

Contract the circuit breaker

Translate the pilot into enforceable schedules:

  • scope and applicability: exact service, entity, State/facility branch, allowed and prohibited use, acceptance, and change procedure;
  • people and locations: named entities, approved countries and roles, screening, devices, remote-access path, substitution, and downstream approval;
  • technology provenance: models, platforms, components, producers, controllers, parents/subsidiaries, endpoints, update channels, prohibited sources, attestation, and change notice;
  • data and AI: classes, purposes, positive-control conditions, training/retention/deletion, logs, permissions, model change, external-user input, human review, public attribution, inventory, and disablement;
  • code and security: repository, AI annotations, SBOM, licenses, secure lifecycle, tests, vulnerabilities, remediation, monitoring, incident, rollback, and recovery;
  • authority: explicit read/write/tool/transaction/communication/delete limits, human gates, appointing authority, release, suspension, and emergency access;
  • records and accessibility: custody, export, search, printable production, audit history, schedule/hold, ACR, task testing, exceptions, alternative means, and remediation;
  • commercials: work breakdown, rates, caps, platform costs, buyer work, evidence, warranty, reserve, milestones, invoice proof, and disputed work;
  • rights: background IP, contributor assignments, third-party and open-source materials, model and training-data diligence, deliverables, inventions, confidentiality, and destination-country formalities;
  • exit: source, build, infrastructure, configuration, inventories, data, records, models, evaluations, accounts, credentials, deletion/disablement/removal where applicable, transition assistance, and acceptance.

Attach evidence formats and response clocks. Require the supplier to disclose uncertainty promptly. Do not make the provider warrant a legal conclusion it cannot control; require facts, cooperation, prohibited action, and buyer-owned determinations.

Kansas outsourcing red flags

  • The provider treats the country where a developer sits as proof that every model, endpoint, component, or device is eligible.
  • A State use case still relies on the superseded 2023 AI policy without checking current ITEC 6200-P.
  • Sensitive inputs enter AI when only some of the six required conditions are demonstrated.
  • “Zero retention” excludes safety logs, support copies, embeddings, traces, backups, or subprocessors.
  • An embedded AI feature is absent from the model and service inventory.
  • An agent has broad credentials and a UI stop button but queued jobs and alternate endpoints continue.
  • State-device/network prohibition is treated as a generic ban on international people or ignored because the model is accessed through a wrapper.
  • A covered genetic facility checks only the reseller and not producer, domicile, ownership, control, subsidiary, operational software, or device origin.
  • Unclassified State data is treated as public instead of Restricted pending classification.
  • AI-generated code is not annotated, independently reviewed, or bound to release evidence.
  • A generic SBOM is offered as proof of model ownership, data flow, and corporate control.
  • Public AI has no perceptible attribution, uncertainty escalation, timely human intervention, or correction route.
  • An accessibility scanner score replaces release-specific task and assistive-technology evidence.
  • The supplier decides whether an event is a statutory breach before giving the buyer immediate facts.
  • Records exist only in the supplier’s chat interface and cannot be searched, printed, held, or migrated with audit history.
  • Every deadline says “Central time” even though the buyer’s actual Kansas site has not been recorded.
  • The quote omits buyer authority work, provenance, evidence, remediation, accessibility, records, recovery, and exit.
  • The contract grants the supplier authority to change models or subprocessors silently.
  • Exit promises “data export” without source, build, configurations, prompts, evaluations, logs, inventories, credentials, deletion, and replacement operation.
  • Marketing claims imply a Kansas office, State approval, medical eligibility, client relationship, certification, or approved AI without evidence.

Frequently asked questions

Can a Kansas company outsource software development outside the United States?

Yes, when applicable law, contract, customer commitments, data rights, security, export controls, sector obligations, and delivery evidence permit it. Team location is only one factor. The buyer should approve the exact entity, people, countries, data, tools, models, components, actions, release, incident path, and exit.

Does Kansas ITEC 6200-P apply to every private business?

No. The policy governs listed Executive Branch entities and defines entity to include agents and contractors acting for them. A private company can adopt its controls voluntarily, but should not present Executive Branch policy as universal private law.

What replaced Kansas’s 2023 generative-AI policy?

ITEC 6200-P took effect May 19, 2026 and expressly cancels and supersedes OITS Policy 8200. It covers broader AI, including internal, external, agentic, and autonomous use, and adds detailed sensitive-data, procurement, inventory, intervention, and review controls.

What are the six conditions for sensitive State information in AI?

No input/output retention or training; no dissemination without appointing-authority permission; deletion/removal capability; interaction logs accessible to the entity; no runtime model modification or retraining without authority; and intended-function-only, automatically deleted inputs for external users. The exact policy and entity procedure govern covered use.

Does a provider’s enterprise AI plan prove those conditions?

No. Verify the exact SKU, tenant, endpoint, region, configuration, contract, subprocessors, logs, deletion path, and change behavior. Capture a signed attestation and technical test for the project.

Are all foreign AI platforms prohibited in Kansas?

No. Section 75-4720 defines an AI platform of concern and applies its access prohibition to State-issued devices and State-operated networks, with a narrow investigative exception. Apply the current definition and facts; do not turn it into an unsupported ban on all foreign technology or people.

Does the genetic-technology rule apply to every Kansas health application?

No. Section 65-449 has defined medical/research facility and genetic-analysis technology scope. A qualified owner should determine applicability. When it applies, provenance must cover devices and operational or research software, not only the visible vendor brand.

How should unclassified State data be treated?

The Kansas data standard says an unclassified data item or system is automatically Restricted. Do not use it in an international or AI path until the owner classifies it and authorizes the corresponding controls.

Must AI-generated code be marked?

For covered State work, ITEC 6200-P says all use of AI-generated code must be annotated. Higher-risk code also requires qualified human review or appropriate testing, and implementation follows documented business and security risk mitigation.

Can an AI prompt, agent trace, or review become a Kansas government record?

Potentially, depending on purpose, creation, receipt, custody, and applicable law and schedules. Preserve export, search, print, retention, audit-history, and hold capabilities; let the designated custodian and counsel decide treatment.

Does a breach affecting more than 1,000 consumers require Kansas Attorney General notice under section 50-7a02?

That section adds notice to nationwide consumer-reporting agencies for more than 1,000 consumers at one time. The Attorney General has enforcement authority, but the text does not create a general 1,000-person Attorney General reporting rule. Other laws or contracts may create additional paths.

How quickly should an international supplier report a possible event?

Immediately under a contract-defined factual relay—typically measured in minutes or hours for material events—then through progressive updates. The buyer needs time to investigate misuse, preserve evidence, contain safely, and make its own legal and operational decisions.

Is all of Kansas in Central time?

No. The federal boundary divides Kansas between Central and Mountain zones. Use the buyer site’s actual IANA identifier and dated offsets rather than a statewide label or informal abbreviation.

Which delivery country is best for a Kansas buyer?

There is no universal winner. Compare the actual team and jurisdiction for capability, overlap, legal entity, contributor rights, data transfer, security, provenance, English and domain fluency, continuity, complete cost, and exit. Use country pages as research inputs, not automatic rankings.

Is Outsourcing.ai located in Kansas?

No Kansas location is claimed. Outsourcing.ai is an online research and delivery platform for U.S. buyers evaluating work with suitable international teams.

Buyer checklist

  • Define the outcome, excluded uses, acceptance result, budget, owner, and exit.
  • Record ordinary private, State entity/contractor, State device/network, and covered facility applicability separately.
  • Identify every provider entity, contributor, supervisor, country, device, replacement, and subprocessor.
  • Classify data and systems; keep unclassified State items Restricted pending owner action.
  • Map inputs, prompts, retrieval, embeddings, outputs, logs, analytics, support, backups, and deletion.
  • Classify AI as internal/external and assistive/generative/agentic/autonomous by actual action authority.
  • Prove all six positive-control conditions before sensitive State input.
  • Inventory model, platform, endpoint, owner/controller, producer, domicile, parents/subsidiaries, components, and update channels.
  • Block and recheck prohibited State device/network AI paths where applicable.
  • Determine covered-facility scope and prove genetic device/software origin before use where applicable.
  • Constrain tools, credentials, actions, transactions, communications, spend, volume, duration, and environments.
  • Test human intervention, uncertainty escalation, queued-action cancellation, credential revocation, rollback, and complete disablement.
  • Disclose AI integrations and bind provider retention/training, deletion, logs, training-data, anomaly, and change attestations.
  • Annotate AI-generated code and preserve qualified review, SBOM, SAST/DAST/composition, remediation, and release evidence.
  • Confirm contributor assignments, background IP, third-party licenses, model/training rights, and destination formalities.
  • Test public attribution, correction, appeal, and human route for external AI.
  • Test keyboard, screen reader, zoom/reflow, errors, documents, widgets, mobile path, and alternative means.
  • Export, search, print, hold, migrate, and schedule representative records with access/change/delete history where applicable.
  • Exercise immediate maintainer-to-owner facts, misuse investigation support, containment, recovery, and progressive updates.
  • Use actual IANA zones, UTC timestamps, named decision windows, and explicit handoff envelopes.
  • Compare complete cost, buyer-retained authority work, evidence, downside reserve, and exit.
  • Run a paid pilot and make pass/fail evidence part of contracting.
  • Reopen the circuit on material data, model, control, component, autonomy, facility, purpose, provider, country, or incident change.
  • Rehearse source/build/data/record/account/credential/deletion handover with a replacement operator.

The exit test

The work is not portable because a repository was transferred. A replacement operator should be able to identify the accepted release; reproduce the build; explain AI and component provenance; verify licenses; recreate infrastructure; restore data; inspect prompts, evaluations, logs, and decisions; locate annotated AI code; operate the service; exercise human intervention; open the circuit breaker; cancel queued actions; revoke credentials; export and print records; meet accessibility acceptance; roll back safely; and continue without hidden supplier accounts.

For covered State AI, reconcile the inventory, permissions, model endpoints, input/output stores, logs, retention, public attribution, unresolved corrections, training settings, and annual-review date. For a prohibited State platform path, prove account deletion and device/network disconnection. For an applicable genetic-technology path, preserve the authorized removal, permanent disablement, replacement, migration, validation, and disposal evidence. For every lane, revoke people and machine identities, rotate buyer secrets, close vendor access, resolve retained copies, and record exceptions.

If the buyer cannot prove origin, authority, stop, record, recovery, and replacement operation, the circuit is still dependent on the supplier. Fix that before the final invoice, not after termination.

Evidence ledger

Sources used on this page

  1. ITEC Policy 6200-P — Artificial Intelligence Acceptable Use Policy — Kansas Information Technology Executive Council. Supports: Current May 19, 2026 Executive Branch policy distinguishing internal, external/customer-facing, generative, agentic, and autonomous AI; six conditions for sensitive inputs; human review and intervention; public attribution; code review and annotation; contractor disclosure and attestations; training-data diligence; AI inventory; suspension; annual review; and significant-capability reassessment. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  2. Kansas Statutes section 75-4720 — Artificial intelligence platforms of concern — Kansas State Legislature. Supports: Current prohibition on access to an AI platform of concern from State-owned or State-issued employee devices and State-operated networks, required deactivation and deletion of State accounts, the narrow law-enforcement and cybersecurity exception, and operative definitions. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  3. Kansas Statutes section 65-449 — Divestiture of genetic sequencers and related software produced by foreign adversaries — Kansas State Legislature. Supports: Current, separately scoped prohibition and replacement requirement for covered Kansas medical and research facilities using genetic sequencers or operational or research software for genetic analysis produced in or by defined foreign-adversary, state-owned, domiciled, subsidiary, or controlled sources. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  4. ITEC-8010-A — Kansas Data Compliance Requirements — Kansas Information Technology Executive Council. Supports: Official State data-governance standard for Public, Private, and Restricted classification, the automatic Restricted default for unclassified data or systems, owner accountability, lifecycle protection, access, storage, transfer, retention, and disposal controls. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  5. ITEC 7050-P — Secure System Development Policy — Kansas Information Technology Executive Council. Supports: Current July 2025 secure-development policy covering State Restricted-Use Information and external-facing systems, including third-party vendor code, secure lifecycle controls, software bills of materials, static and dynamic testing, composition analysis, remediation, and release evidence. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  6. ITEC 7012-P — Remote Access Security Policy — Kansas Information Technology Executive Council. Supports: Current State policy for remote access to non-public Kansas networks, systems, applications, and services, including third parties, approved remote technologies, authorization, MFA, least privilege, monitoring, timeout, revocation, and review. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  7. ITEC 1210-P Revision 4 — Information and Communication Technology Accessibility Policy — Kansas Information Technology Executive Council. Supports: Current mandatory Executive Branch accessibility policy for procured, developed, maintained, or contractually provided ICT, including Revised Section 508, ADA Title II Subpart H, WCAG 2.1 A and AA, documented best-meets exceptions, alternative means, and approval before deployment. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  8. Kansas KARS Project Overview — Kansas State Office of Information Technology Services. Supports: Current project-stage evidence for State initiatives, including stakeholder and cost plans, risk assessment, architecture, code ownership, accessibility conformance report, records retention, security, data compliance, milestones, and Executive Authority approval. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  9. Kansas Statutes sections 50-7a01 and 50-7a02 — Protection of consumer information — Kansas State Legislature. Supports: Current definitions and breach duties for covered Kansas personal information, including owner or licensee investigation and resident notice, maintainer-to-owner notice after discovery, law-enforcement delay, alternative compliance, the more-than-1,000-consumer reporting-agency path, and enforcement. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  10. Kansas Statutes chapter 45, article 4 — Public records preservation — Kansas State Legislature. Supports: Current State records-preservation framework defining government records across forms and media and prohibiting destruction or disposal except as permitted by law or approved retention and disposition schedules. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  11. Kansas Statutes section 45-501 — Records made on electronically accessed media — Kansas State Legislature. Supports: Current requirements for preservation, examination, ready use, printable production, security procedures, and a permanent access/change/deletion record when required agency records are maintained only on electronically accessed media. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  12. Uniform Time — U.S. Department of Transportation. Supports: Official explanation that 49 CFR part 71 contains the national time-zone boundaries and that time-zone boundary changes are governed federally, supporting location-specific rather than statewide clock assumptions. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  13. Artificial Intelligence Risk Management Framework — National Institute of Standards and Technology. Supports: Voluntary Govern, Map, Measure, and Manage structure for translating Kansas-specific AI scope, data, autonomy, provenance, human-accountability, monitoring, and decommissioning decisions into evidence. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  14. Secure Software Development Framework — National Institute of Standards and Technology. Supports: Primary secure-development practices for protecting software, producing well-secured releases, responding to residual vulnerabilities, and giving buyers repeatable evidence across contributors and suppliers. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  15. Time Zone Database — Internet Assigned Numbers Authority. Supports: Maintained time-zone identifiers and transition rules for calculating dated overlap between the buyer's actual Kansas location and proposed international delivery cities. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
  16. Directory of Intellectual Property Offices — World Intellectual Property Organization. Supports: Official destination-country intellectual-property office links for checking contributor, software, model, data, invention, copyright, and assignment questions rather than assuming a Kansas contract alone resolves them. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.

Next scheduled review: October 15, 2026. Corrections: hello@outsourcing.ai.