New Hampshire buyer guide
Outsourcing software development from New Hampshire
A New Hampshire guide to international software and AI outsourcing: AI authority, decommission proof, privacy roles, child-facing systems, incidents, cost, and exit.

New Hampshire outsourcing at a glance
| Proposed work | First buyer decision | Evidence required before access |
|---|---|---|
| Ordinary private software, automation, support, analytics, or AI | Prove why the work remains outside any activated State-system, consumer-data, child-directed communication, insurance-licensee, customer-contract, export, or other regulated lane | Work package, entity, named people and locations, system and data boundary, synthetic-data plan, permissions, model and service inventory, acceptance, release owner, recovery, and exit |
| AI used in a computer system operated by a New Hampshire State agency | Determine Chapter 5-D applicability, exceptions, current DoIT policy, responsible human owner, prohibited-use analysis, inventory path, and procurement evidence before implementation | Use case, system and model inventory, data inputs, outputs, limitations, affected decisions, human review, interaction disclosure, approved procedures, testing, removal plan, annual-report fields, and buyer acceptance |
| Personal data processed on behalf of a potentially covered controller | Determine Chapter 507-H scope and the operation-specific controller or processor role rather than assigning one label to the whole provider | Written instructions, purpose, data types, duration, confidentiality, rights assistance, security and breach support, assessment inputs, subprocessor objection and flow-down, return or deletion, and compliance report |
| Profiling, targeted advertising, sale, or sensitive-data processing within a covered controller’s operation | Decide whether a documented data protection assessment is required and who owns it | Processing map, benefits, risks, safeguards, deidentified-data use, consumer expectations, context, relationship, decision, version, review trigger, and protected assessment repository |
| Responsive generative communication that may be directed to a child | Determine the actual product, operator, audience, communication, knowledge, intent, and statutory exception facts; do not convert the statute into a slogan | Audience and product classification, system prompt and policy versions, model and tool path, content test set for the listed conduct, escalation, evidence preservation, release approval, rollback, and retirement |
| Suspected breach involving personal information maintained for another owner or licensee | Preserve the immediate non-owner-to-owner path and the buyer’s separate misuse and notice analysis | Discovery time, affected systems and data, access and acquisition facts, owner, licensee, maintainer, preservation, immediate escalation, cooperation record, containment, restoration, and decision log |
| Insurance-licensee system or nonpublic information accessible to a third-party provider | Determine Chapter 420-P licensee scope, program ownership, provider oversight, investigation, records, and commissioner-notice path | Due diligence, written security requirements, access register, tests, incident-response roles, prompt investigation packet, licensee confirmation, five-year event-record custody, conditional three-business-day notice inputs, updates, and exit |
These are classification prompts, not conclusions about a particular organization, product, message, event, or contract. Chapter 5-D is expressly about computer systems operated by State agencies and states exceptions. Chapter 507-H has thresholds, exemptions, definitions, and operation-specific roles. RSA 507:8-k has specific owner-or-operator, product, knowledge, intent, conduct, remedy, and exception elements. Chapter 420-P establishes standards for licensees, not every New Hampshire company. Counsel and accountable buyer owners should confirm the current text and the exact facts before a material decision.
The distinct New Hampshire model: AI authority and decommission relay
Many AI procurement processes prove how a system enters production but say little about how an unsuitable use is stopped, removed, and accounted for. New Hampshire’s State-agency AI chapter makes that omission especially visible. It requires State agencies within scope to review their computer systems and procedures, remove prohibited AI systems, modify inconsistent procedures, make new deployments comply, and support a public reporting process that distinguishes identified systems, prohibited and removed systems, allowed systems, procurement and use procedures, and newly purchased systems.
That is not a private-sector rule. It is, however, a useful reason for every buyer to require symmetrical evidence at both ends of the lifecycle. “We deployed it” is incomplete without “we can identify it, suspend it, remove it, revoke it, export what must remain, delete what should not remain, and prove the resulting state.”
Build an AI authority and decommission relay with seven records:
- Applicability record: buyer entity, system operator, statutory or contractual source, exception analysis owner, policy version, customer requirements, and decision date.
- AI inventory record: use case, owner, provider, service, model and version, hosting and processing regions, integrations, agents and tools, input and output data, users, permissions, purchase or renewal, and status.
- Decision and interaction record: recommendation or decision, reversibility, affected rights or operations, responsible human reviewer, known limitations, escalation, AI-interaction disclosure, unreviewed-content disclosure, and acceptance.
- Supplier authority record: named person or service identity, purpose, allowed systems and actions, data boundary, environment, start and expiry, approver, observation, and revocation.
- Change and evidence record: prompt, policy, model, retrieval corpus, tool, interface, subprovider, security, accessibility, evaluation, incident, or law change; required review; tests; decision; and release.
- Removal record: stop authority, disablement, routing change, access revocation, secret rotation, retained data, exported evidence, deleted artifacts, downstream copies, validation, and residual obligations.
- Exit and reporting record: final inventory state, accepted deliverables, open risk, holds, warranties, annual-report fields where applicable, transition assistance, and buyer sign-off.
The supplier can create and maintain evidence, but it should not unilaterally decide that Chapter 5-D does not apply, that an AI use is permitted, that a human review is adequate, that disclosure is unnecessary, that a harmful communication falls outside RSA 507:8-k, that an event is not reportable, or that decommission is complete. Those decisions belong to identified buyer authorities with counsel or specialist input where needed.
Classify the entity, operation, audience, and consequence first
Do not start an RFP with “AI team in Latin America” or “offshore developers.” Start with the work unit. A single New Hampshire organization can have a public marketing site, employee assistant, customer support bot, consumer profiling operation, State-agency contract, insurer integration, research prototype, and general back-office system. Each can activate different requirements.
Record the following for every work package:
- Buyer and operator: legal entity, business unit, State-agency relationship, license status, customer contract, system operator, product owner, data owner, procurement owner, security owner, and legal decision owner.
- System: application, model, hosted service, API, agent, retrieval store, plug-in, integration, decision engine, content generator, support queue, logging platform, and every production or test environment.
- Operation: collection, generation, classification, recommendation, decision, profiling, sale, targeted advertising, sensitive-data use, support, monitoring, security investigation, content delivery, export, deletion, or another purpose.
- Audience and subject: employee, adult consumer, child, resident, public user, claimant, insured, producer, applicant, beneficiary, or unknown visitor; record how audience or age is known or inferred and the consequence of error.
- Information: personal data, personal information under a breach law, sensitive data, nonpublic information, credentials, prompts, outputs, conversations, feedback, source code, model artifacts, logs, and derived data.
- People and locations: every contributor and employer, subprovider, work city, storage and processing region, support location, production administrator, and incident responder.
- Authority: view, prompt, label, train, retrieve, generate, moderate, recommend, decide, approve, deploy, notify, stop, restore, retain, delete, and disclose.
- Consequence: reversible draft, public material, service denial, rights or freedom, critical operation, financial or reputational harm, child harm, regulatory decision, or material business disruption.
- Exit: inventory owner, exports, format, deletion, downstream propagation, legal hold, revocation, replacement-team test, and retained obligations.
If critical facts are missing, keep the provider in an isolated prototype using synthetic, public, or buyer-approved data. A polished vendor demonstration is not proof that the real operation belongs in the ordinary lane.
Keep private delivery separate from State-agency AI duties
Chapter 5-D applies to computer systems operated by a State agency as defined in the chapter. It states exceptions for systems used in research by State-funded institutions of higher learning and installed consumer systems in common personal use, including the example in the statute. It does not apply to every private company headquartered in Manchester, Nashua, Concord, Portsmouth, or elsewhere in New Hampshire.
That boundary should appear in the project record. If a private product does not enter the State lane, identify the actual private, customer, contractual, federal, sector, and destination-country sources that do apply. If a supplier is supporting a State agency or a system operated by one, do not assume the buyer’s ordinary commercial template is enough. Obtain the authoritative scope, current DoIT policy and procedure set, approved environment, procurement terms, required inventory fields, and named State owner.
For ordinary private work, a strong baseline still includes:
- buyer-controlled repositories, cloud organizations, domains, release signing, production credentials, billing, and backups;
- named contributors and disclosed work locations rather than a provider brand alone;
- narrow accounts with expiration, separate administration, and prompt revocation;
- synthetic, minimized, masked, or specifically approved development data;
- a model and service register covering versions, hosting, integrations, retention, training use, subprocessors, and change notices;
- code review, testing, provenance, dependency controls, evaluation evidence, rollback, and recovery;
- a faster contractual incident path than any outer statutory decision deadline; and
- exportable code, infrastructure definitions, prompts, evaluations, decisions, runbooks, logs, and transition records.
The goal is not to make private delivery look like a State system. It is to make the lane and its reasons explicit, then reclassify it if the buyer, operator, customer, data, audience, model, use, or consequence changes.
Translate Chapter 5-D into State-system supplier controls
Chapter 5-D prohibits three categories of AI use by State agencies: classification that results in unlawful discrimination based on the listed kinds of characteristics; real-time remote biometric identification for surveillance in public spaces except the stated law-enforcement warrant path; and deepfakes used for a deceptive or malicious purpose. The supplier workflow should preserve the exact statutory language and avoid expanding or narrowing it through shorthand.
Before a State-system supplier begins, create a use-case dossier:
| Control question | Supplier evidence | Buyer authority |
|---|---|---|
| What is the AI use? | Functional description, service and model versions, prompts or rules, inputs, outputs, integrations, users, and affected process | State system and product owners classify the use and source |
| Could the use enter a prohibited category? | Test cases, data and feature inventory, biometric capability, content generation path, abuse analysis, limitations, and vendor representations | Named State and legal owners decide whether use is permitted, modified, isolated, or removed |
| Does the system recommend or decide something irreversible? | Decision flow, reversibility test, consequence, confidence, appeal or correction path, and known limitations | Responsible human owner approves the review point before effect |
| Is generated material human reviewed? | Creation and revision trace, reviewer, timestamp, editing record, release state, and disclosure behavior | Responsible owner decides whether review is sufficient or disclosure is required |
| Does a person interact with AI? | Interface and indirect-interaction map, disclosure placement, accessibility test, and failure-mode capture | Product and responsible policy owners accept the interaction design |
| Can the system be removed? | Disablement, dependency graph, routing fallback, data and secret disposition, regression test, and evidence packet | Buyer triggers removal and accepts the post-removal state |
| What enters annual reporting? | Inventory status, purchase or deployment date, permitted or removed state, procedures, evidence links, and changes | DoIT and the accountable agency determine report content and publication |
Human review cannot be an ornamental checkbox. For a recommendation or decision that cannot be reversed once implemented or executed, the statute calls for review before it takes effect by a human in an appropriately responsible position who knows the system’s limitations. The implementation should identify which decisions are irreversible, how the system pauses, what the reviewer can see, what limitations are presented, how the reviewer changes or rejects the result, and what evidence remains. A supplier “confidence score” is not equivalent to informed review.
Similarly, separate two disclosure paths. Material produced by generative AI that has not been reviewed and possibly edited by an appropriately responsible human follows the statute’s AI-generated-content disclosure path. Other direct or indirect human interaction with an AI system follows the interaction disclosure path. The buyer should test visible wording, placement, timing, accessibility, channel consistency, API and embedded contexts, localization, and failure modes under the authoritative policy—not let an overseas developer invent a legal conclusion in the interface.
Make removal and decommission a release requirement
The State-agency compliance section addresses prohibited systems being removed and inconsistent procedures being modified. This makes a useful acceptance principle concrete: a system is not operationally governable if the buyer cannot remove it without losing essential service, records, or authority.
Every AI deployment should ship with a decommission packet containing:
- the exact inventory items being retired, including aliases, versions, endpoints, keys, queues, data stores, retrieval corpora, scheduled jobs, plug-ins, agents, and downstream dependencies;
- a buyer-approved fallback for essential service and a test showing that traffic no longer reaches the retired path;
- revoked human and machine identities, rotated shared secrets, removed webhooks, disabled service accounts, and verified permission propagation;
- exported records needed for audit, rights, investigation, continuity, contract, reporting, or legal hold;
- documented deletion for prompts, outputs, embeddings, fine-tuning data, logs, caches, backups, and subprovider copies where deletion is required and technically available;
- preserved evidence showing who approved removal, when each action occurred, what verification passed, what data remains, and why;
- updated user procedures, disclosures, incident playbooks, diagrams, procurement and renewal records, and annual-report inputs; and
- a replacement-team exercise proving the buyer can operate, restore, and explain the resulting system without the outgoing provider.
A provider dashboard that says “deleted” is only one input. Request the object scope, API or administrative action, time, downstream status, retention exception, recovery or backup behavior, and verification result. If deletion is delayed by a fixed backup cycle, document the access restriction and final confirmation point rather than pretending it happened instantly.
Build a controller–processor operation ledger under Chapter 507-H
Chapter 507-H became effective January 1, 2025 and has defined scope, thresholds, exemptions, terms, rights, and enforcement. Do not infer applicability from a New Hampshire mailing address or from the presence of any personal data. Confirm the current statute and the buyer’s facts.
When the supplier processes personal data on behalf of a covered controller, section 507-H:7 makes the relationship operational. The processor must follow the controller’s instructions and assist with rights requests, security and breach obligations, and data protection assessments, taking account of the stated circumstances. A binding contract must set out instructions, nature and purpose, data type, duration, and both parties’ rights and obligations. It also addresses confidentiality, return or deletion at the controller’s direction, compliance information, subcontractor objection and flow-down, and reasonable assessments or an independent assessment report.
Turn those requirements into one row per processing operation:
| Operation field | Minimum evidence |
|---|---|
| Instruction | Versioned purpose, allowed actions, prohibited actions, data fields, subjects, systems, regions, retention, and decision owner |
| Role | Controller or processor determination for this operation, facts supporting it, reviewer, and change trigger |
| Rights | Request intake, identity and authorization route, data discovery, correction, deletion, opt-out propagation, response evidence, and exceptions |
| Security and breach | Controls, logging, alert ownership, immediate supplier escalation, preservation, investigation support, restoration, and decision authority |
| Assessment support | Processing map, benefits, risks, safeguards, model and profiling facts, deidentified-data use, expectations, context, and evidence location |
| Subprocessor | Entity, service, operation, data, location, notice, objection window, contract flow-down, security evidence, and exit dependency |
| End of service | Return format, deletion objects, retention exception, backups, confirmation, access revocation, and buyer acceptance |
Role is fact-based and can change by operation. Section 507-H:7 explains that a person not limited by controller instructions, or failing to follow them, can be a controller for that processing. If a provider begins determining purpose and means alone or jointly, it may move into controller status for that operation. Contract labels do not cure operational role drift. Detect it with change review, logs, model training configuration, analytics, product telemetry, new integrations, support access, and subprovider monitoring.
Connect heightened-risk assessments to engineering changes
For a covered controller, section 507-H:8 identifies targeted advertising, sale, sensitive-data processing, and certain profiling as heightened-risk activities requiring documented data protection assessments. The assessment weighs benefits against potential risks as mitigated by safeguards and accounts for deidentified data, reasonable consumer expectations, context, and the controller’s relationship with the consumer. The requirements apply to processing activities created or generated after July 1, 2024 and are not retroactive.
Do not file an assessment once and detach it from delivery. Link it to:
- the operation, data lineage, model, audience, decision, and release version;
- the asserted benefit and the metric that could show whether it exists;
- each foreseeable harm and the engineering, product, policy, or human safeguard intended to reduce it;
- evaluation datasets and limitations, including who is underrepresented or out of scope;
- the actual consumer relationship and expectations rather than an abstract persona;
- the residual risk, accountable acceptor, expiry, and conditions for pause;
- triggers such as a new purpose, feature, model, data source, recipient, audience, decision, interface, country, subprovider, or failure; and
- the confidential repository and controlled route for a lawful Attorney General request.
The supplier should return evidence for the controller’s assessment, not write a self-serving conclusion that the product is lawful. A good pilot proves that a model, prompt, or data-path change opens the assessment gate before production and that release remains blocked until the named buyer owner resolves it.
Treat RSA 507:8-k as a narrow product-content and intent gate
RSA 507:8-k took effect January 1, 2026. Its first paragraph addresses an owner or operator of the listed kinds of online services, including specified AI chat systems whose sole purpose is responsive open-ended generative communication, when the owner or operator knows at the time it directs the communication to a child that the communication is made with intent to facilitate, encourage, offer, solicit, or recommend imminent participation in the listed conduct. The statute lists sexually explicit conduct, production of a visual depiction of that conduct, illegal drug or alcohol use, self-harm or suicide, and violent crime against another person.
The law includes an Attorney General action and cure process, a private damages provision, and express exceptions for certain cloud, telecommunications, or information-service provision of third-party content and for an AI chat program or character integral or incidental to specified entertainment experiences. Those elements matter. Do not describe the law as a general age-assurance mandate, a universal chatbot ban, or a duty imposed on every cloud provider.
For a product that might enter this perimeter, build a content-intent gate:
- identify the owner, operator, service, sole-purpose question, content source, audience, child-directed facts, and potential exception;
- map system, developer, provider, fine-tune, retrieval, tool, and human-control contributions to the communication;
- preserve versioned system prompts, policies, moderation settings, tool permissions, retrieval sources, escalation logic, and release approvals;
- create adversarial tests tied to the listed conduct, including indirect phrasing, role play, multilingual prompts, long conversations, evasion, model or prompt changes, and tool use;
- test safe redirection and crisis escalation with subject-matter owners, without promising a perfect content filter;
- restrict supplier access to sensitive conversation data and use synthetic or appropriately controlled test material wherever possible;
- log enough to investigate a credible allegation while minimizing data, controlling retention, and respecting other applicable duties;
- stop or roll back a failing model, prompt, tool, retrieval source, or release without waiting for the provider’s next commercial update; and
- keep product, legal, safety, communications, preservation, and response authority with named buyer owners.
The supplier contract should require prompt escalation of relevant test failures and credible events. It should not ask an overseas moderation team to decide New Hampshire liability alone or make public statements without buyer authorization.
Preserve the general breach owner–maintainer relay
RSA 359-C:20 separates the person doing business in the State that owns or licenses computerized data containing personal information from the person or business that maintains such data for someone else. The owner or licensee has the prompt misuse-likelihood determination and affected-individual notice path described in the statute. A non-owner maintainer must notify and cooperate with the owner or licensee immediately following discovery when the statutory acquisition fact is present.
Translate that into an incident relay that begins before legal certainty:
- supplier discovery, system, environment, time, reporter, confidence, and observed facts;
- preservation of logs, access records, images, alerts, model or service traces, and affected configurations;
- safe containment authority and actions, including what the supplier may do immediately and what needs buyer approval;
- data owner, licensee, maintainer, elements, encryption, key, access, and acquisition facts;
- likely misuse analysis inputs without letting the provider declare the legal conclusion;
- immediate named buyer escalation, backup route, acknowledgement, and repeated update cadence;
- affected people estimate, restoration, recovery validation, communications hold, regulator and notice decision owners; and
- a final decision and lessons record tied to control remediation and supplier exit.
Contractual escalation should be faster than any outer notice path. “Immediately following discovery” should not become “after our provider finishes a root-cause report.” The first report can be incomplete; it should be time-stamped, bounded, and followed by progressively better evidence.
Keep insurance-licensee cybersecurity on its own path
Chapter 420-P establishes New Hampshire’s insurance data-security standards for licensees. Its third-party-service-provider controls, investigation duties, records, and commissioner notices should not be copied onto every private buyer as if they were universal law. First determine whether the buyer is a licensee and which exemptions, federal or state frameworks, and event facts apply.
For an in-scope licensee, the chapter addresses due diligence in selecting a third-party service provider and requiring appropriate administrative, technical, and physical measures for accessible or held information systems and nonpublic information. The information security program adjusts with technology, data sensitivity, threats, outsourcing arrangements, and other business change. The incident-response plan includes roles, authority, communications, remediation, documentation, and post-event revision.
If a licensee learns that a cybersecurity event has or may have occurred, the licensee or its designated outside vendor or service provider conducts a prompt investigation. When the possible event is in a provider-maintained system, the licensee completes the statutory investigation steps or confirms and documents that the provider did so. The licensee keeps records about cybersecurity events for at least five years. Conditional commissioner notification is within three business days of the determination that an event occurred when the stated criteria are met, and the statute imposes continuing updates for material changes. For a provider-system event, the deadline computation begins on the day after provider notice or the licensee’s actual knowledge, whichever is sooner.
The supplier interface therefore needs:
| Evidence clock | Supplier operation | Licensee authority |
|---|---|---|
| Continuous | Named people, systems, data, access, subproviders, controls, testing, changes, and exit readiness | Approve provider scope, due diligence, requirements, access, exceptions, and review |
| Possible event | Immediate internal escalation, preserve, investigate or support investigation, determine scope and affected nonpublic information, restore security, and update | Decide investigation leadership, confirm provider work, direct containment, and preserve privilege where appropriate |
| Determination | Return exact time, criteria facts, affected consumers and operations, provider roles, control lapse, remediation, and contact | Determine whether an event occurred and whether commissioner and consumer paths activate |
| Three-business-day path when triggered | Maintain rapid evidence channel and correct material facts | Submit and authorize commissioner notice; do not delegate the legal conclusion by silence |
| Five-year event record | Return a complete, indexed, immutable or appropriately protected record and corrections | Own custody, retention, production, access, and final destruction |
Use a named business-day calendar and backup decision-makers. The three-business-day phrase is not a promise that every cyber signal is reportable; it is a reason to make the determination evidence available quickly when the buyer’s legal owners need it.
Design the Eastern-time authority window
New Hampshire buyer cities use the America/New_York IANA time-zone path. That does not make any country automatically nearshore or offshore. The relevant question is whether the exact contributor city, on the actual project dates, provides enough overlap for the decisions that cannot safely wait.
The buyer should calculate a dated schedule for each named work city and define three lanes:
- Build lane: focused supplier work that can proceed within approved scope using recorded assumptions and no production authority.
- Decision lane: recurring overlap for design choices, access grants, privacy and AI gates, risk acceptance, release, and decommission approval.
- Incident lane: continuously tested route to named buyer and provider responders, independent of ordinary meeting hours.
A delivery packet should arrive before the New Hampshire owner starts the day: change summary, linked artifact, tests, evaluation outcomes, data or model change, unresolved questions, recommended decision, rollback, and evidence location. The buyer’s response should record the decision, owner, rationale, permitted next action, expiry, and new evidence needed.
Test both U.S. and contributor clock transitions. Do not use a static “five hours ahead” field for a year-long engagement. IANA zone identifiers, dated calendar tests, human-sustainable schedules, backup owners, holiday calendars, and recorded handoffs are more reliable than country labels.
Evaluate destination countries and intellectual-property custody
The New Hampshire guide chooses a buyer-control model, not a universal destination. A team in Colombia or Mexico may offer substantial Eastern-time overlap; Poland can support a morning handoff; India or the Philippines may support an overnight build-and-review rhythm. The exact entity, people, cities, data flow, system region, subcontracting, cost, and resilience matter more than the flag.
For every proposed country and contributor, verify:
- contracting entity, beneficial and signing authority, worker relationship, and right to supply the named person;
- current sanctions, export-control, customer, sector, grant, procurement, insurer, and data-location restrictions;
- background, identity, qualifications, reference evidence, and replacement process proportionate to the role;
- creator and inventor obligations, present assignment language where appropriate, further-assurance duties, moral-rights handling, pre-existing materials, open-source and model terms, and destination-country formalities;
- buyer ownership of repositories, cloud, domains, signing, production, models where contractually possible, prompts, evaluation suites, documentation, and backups;
- disclosed subproviders, locations, tools, AI coding assistants, model services, and changes;
- invoice currency, tax assumptions, travel, equipment, security, management, overlap, rework, transition, and failure cost; and
- enforceable return, deletion, access revocation, handover, cooperation, and dispute paths.
Use the WIPO directory as a route to official destination-country offices, then obtain advice for the actual structure. A New Hampshire choice-of-law clause alone does not prove that every creator, employer, subcontractor, model provider, or jurisdictional formality has been handled.
Compare complete cost, not the rate card
Normalize each proposal to a defined outcome and evidence package. A lower hourly rate can produce a higher complete cost when the team needs extensive buyer management, operates with unstable staffing, hides subproviders, lacks testing or documentation, cannot support required review, or leaves the buyer trapped in provider accounts.
Use this model:
Complete cost = supplier fees + buyer management + overlap and handoff + security and privacy + AI evaluation and governance + infrastructure and tools + travel and equipment + rework and delay + incident readiness + transition and exit.
Require each provider to price the same work package, assumptions, acceptance tests, evidence, support period, and exit exercise. Separate recurring production service from a bounded pilot. Identify variable model inference, storage, retrieval, observability, moderation, third-party API, and data-egress costs. Model a plausible failure and replacement scenario, not only the happy path.
The cheapest credible proposal is the one that gives the buyer the accepted result and control at the lowest risk-adjusted complete cost. That may be a nearshore team, an offshore team with an excellent asynchronous system, a hybrid, or a U.S. lead coordinating disclosed contributors. The answer should follow the evidence.
Run a six-to-eight-week paid pilot
Do not grant broad production access to test whether a provider is trustworthy. Use a bounded paid pilot that produces useful work and proves the control plane.
Week 0: classification and baseline
Name the buyer, operator, system, data, audience, AI use, decision consequence, legal and contractual sources, supplier people and locations, subproviders, accounts, and owners. Choose an isolated work package and define what would move it into a different lane.
Weeks 1–2: inventory and evidence path
Create the AI and service inventory, operation ledger, repository map, access register, data map, model and prompt versioning, acceptance tests, incident route, and decommission plan. Test one controller instruction and one rights-support path if relevant. Do not use real sensitive data merely to make the test realistic.
Weeks 3–4: delivery and change gates
Deliver a vertical slice. Test code and model provenance, evaluation coverage, accessibility, security, privacy, human review, disclosure, rollback, and recovery. Introduce a controlled model, prompt, data source, subprovider, or purpose change and confirm that the correct review gate blocks release.
Week 5: adverse scenario
Run the most relevant scenario: prohibited State use discovered, irreversible decision awaiting human review, missing AI disclosure, profiling assessment change, child-content test failure, suspected personal-information acquisition, insurance provider event, or supplier outage. Measure acknowledgement, evidence quality, decision ownership, containment, updates, and recovery.
Weeks 6–7: decommission and exit
Remove one model or service path. Revoke accounts, rotate secrets, export records, delete approved test artifacts, reconcile downstream systems, update the inventory and procedures, and have a replacement engineer reproduce the result from buyer-held materials. Preserve legal or investigation holds instead of mechanically deleting them.
Week 8: decision
Score accepted outcome, evidence completeness, role discipline, change control, accessibility, security, rights support, AI evaluation, incident performance, complete cost, continuity, and exit. Expand only the capabilities that passed. Remediate, re-scope, or reject the rest.
Put the relay into the contract and work order
The master agreement should create enforceable foundations; each work order should activate the exact system, operation, people, data, AI, and evidence requirements. Include counsel-reviewed terms for:
- defined services, deliverables, acceptance, warranties, service levels, support, and remedies;
- named contributors, employers, work locations, replacement, subcontractor notice, objection, and flow-down;
- buyer instructions, allowed purpose, data and system boundaries, roles by operation, confidentiality, retention, return, deletion, and audit or assessment support;
- AI inventory, approved services and models, training-use restrictions, prompt and output handling, model or policy change notice, evaluation, human review, disclosure support, and prohibited-use escalation;
- secure development, provenance, dependencies, vulnerabilities, accessibility, testing, release, rollback, recovery, and evidence;
- immediate operational incident escalation, preservation, investigation cooperation, progressive updates, communications control, restoration, and post-event record;
- intellectual-property creation and assignment, pre-existing materials, open-source, third-party and model terms, further assurances, and infringement allocation;
- buyer-owned accounts and artifacts, access expiry, decommission, transition assistance, export formats, replacement-team test, and verified revocation;
- insurance, liability, indemnity, confidentiality survival, dispute, governing law, and destination-country enforceability appropriate to the deal; and
- change control that prevents a new model, purpose, data source, audience, decision, subprovider, country, or production permission from entering through an informal chat message.
Avoid a contract that says “provider will comply with all laws” but never tells the delivery team what must happen. The obligation ledger should map each activated clause to an owner, system control, evidence artifact, review date, incident route, and exit test.
Red flags for New Hampshire buyers
- The provider says Chapter 5-D applies to every private New Hampshire company or ignores it for a State-operated system.
- A State AI inventory names only the provider and not the service, model, version, data, integration, owner, decision, purchase, or status.
- The system can be launched but cannot be disabled without losing essential records or service.
- “Human in the loop” means a reviewer sees only the AI conclusion and cannot understand limitations, reject it, or stop effect.
- Disclosure is a single footer that is not tested across indirect, embedded, API, accessible, and failure contexts.
- The privacy contract assigns one controller or processor label to the entire provider without an operation-level record.
- A provider uses buyer data for its own analytics or model improvement outside documented instructions without a role and purpose review.
- The team describes RSA 507:8-k as a universal chatbot ban, universal age gate, or perfect-filter requirement.
- Safety testing covers only short English prompts and omits long conversations, evasion, indirect language, model changes, tools, and rollback.
- Incident notice waits for a complete root-cause analysis or routes through an unmonitored general support inbox.
- An insurance-licensee supplier promises to decide whether commissioner notice is legally required instead of returning decision-ready facts.
- “Deletion” excludes embeddings, logs, caches, backups, subprocessors, or service accounts without saying so.
- The buyer does not control repositories, domains, cloud, production keys, release, evidence, backups, and final access revocation.
- The quoted rate omits buyer management, model costs, governance, security, incident readiness, rework, and exit.
Frequently asked questions
Is outsourcing software development outside the United States legal for a New Hampshire company?
It can be, but the answer depends on the buyer, contract, system, data, audience, sector, destination, people, access, and applicable State, federal, customer, export, sanctions, privacy, security, employment, tax, and intellectual-property requirements. Classify the actual work and obtain appropriate advice; do not treat this guide as a legal clearance.
Does New Hampshire Chapter 5-D apply to every private business using AI?
No. The chapter states that it applies to computer systems operated by State agencies as defined there and states exceptions. A private buyer should not claim State compliance or inherit State duties merely because it is located in New Hampshire. A private supplier supporting a State-operated system should obtain the actual scope, policy, procurement terms, and accountable State owners.
What is the most important New Hampshire-specific outsourcing control?
For AI work, require proof at both entry and exit: applicability, inventory, responsible human authority, disclosure, evaluation, release, removal, access revocation, data disposition, procedure update, and accepted final state. Deployment evidence without decommission evidence leaves the buyer exposed to model, policy, provider, or legal change.
Does the child-facing AI provision require every chatbot to verify age?
The current text does not state a universal age-verification mandate for every chatbot. It has specific owner or operator, service, sole-purpose, knowledge, intent, directed-communication, listed-conduct, remedy, and exception elements. Treat it as a narrow product-content and intent classification requiring current legal review, not a marketing summary.
Which country is best for a New Hampshire buyer?
There is no universal winner. Colombia and Mexico may provide useful Eastern-time overlap; Poland may fit morning collaboration; India and the Philippines may fit an overnight delivery system. Score the exact team, cities, entity, data path, model services, authority, evidence, complete cost, resilience, and exit.
Should the provider be the controller or processor under Chapter 507-H?
Determine the role for each processing operation. A provider following the buyer’s instructions may be a processor for one operation and a controller for another if it determines purposes and means. Contract labels should match actual behavior, logs, settings, training use, analytics, and subprovider relationships.
How quickly should an overseas supplier report a suspected incident?
Contract for immediate operational escalation to named buyer owners, with an incomplete but time-stamped first report followed by progressive updates. That gives the buyer time to make any statutory or regulatory determination. Do not use an outer legal deadline as the supplier’s service level.
What should a paid pilot prove?
It should prove a small accepted outcome and the operating system around it: named people and locations, inventory, instructions, access, evaluation, human review, disclosure support, change gates, incident response, rollback, recovery, complete cost, decommission, export, deletion, revocation, and replacement-team continuity.
Can a provider claim that its AI system is compliant with New Hampshire law?
A general claim is not decision evidence. Ask which entity, system, operation, version, requirement, exception, test, owner, date, and artifact the claim covers. The buyer and its advisers retain applicability and acceptance decisions; the provider supplies accurate facts and performs the contracted controls.
Final buyer checklist
- Identify the buyer entity, operator, customer, license, contract, system, data, audience, AI use, decision consequence, and applicable source.
- Keep ordinary private delivery, State-agency AI, consumer privacy, child-directed communication, general breach, and insurance cybersecurity in separate lanes.
- Register every service, model, version, integration, tool, data source, user, permission, subprovider, region, purchase, owner, and lifecycle state.
- Define prohibited-use analysis, human review, interaction disclosure, generated-material disclosure, and release authority where Chapter 5-D applies.
- Map each personal-data operation to instructions, role, rights support, security, assessment, subprocessor, return, and deletion evidence.
- Test the exact child-content conduct and intent risks only when product facts make the lane relevant; preserve statutory exceptions and narrow elements.
- Give suppliers immediate operational incident routes while buyers retain regulator, consumer, and public communications decisions.
- For insurance licensees, test prompt investigation, provider confirmation, five-year record custody, the conditional three-business-day route, and continuing updates.
- Calculate dated overlap from named cities and IANA zones; test normal, decision, and incident paths.
- Review every country, entity, contributor, assignment, subprovider, model service, restriction, and complete-cost assumption.
- Make removal, fallback, export, deletion, access revocation, procedure update, and replacement-team recovery part of acceptance.
- Expand only after a paid pilot proves both the product result and the authority relay.
The durable advantage is not access to a particular provider directory. It is a buyer-owned operating system that can explain why an AI or software service is allowed, who may operate it, what evidence supports the decision, how a human can intervene, when a change must stop, how an incident reaches the right authority, and how the service can be removed without surrendering continuity or proof.
Evidence ledger
Sources used on this page
- New Hampshire RSA Chapter 5-D — Use of Artificial Intelligence by State Agencies — New Hampshire General Court. Supports: Current State-agency AI definitions, applicability, prohibited uses, human review, AI-interaction and unreviewed-content disclosures, compliance review, removal, procedure changes, procurement reporting, and annual public-report requirements. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- State of New Hampshire Use of Artificial Intelligence Technologies Policy — New Hampshire Department of Information Technology. Supports: Official State-government AI policy context for human oversight, transparency, nondiscrimination, privacy, accessibility, continuous monitoring, data protection, and approved use. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- New Hampshire State Government Code of Ethics for AI Systems — Executive Summary — New Hampshire Department of Information Technology. Supports: Official State AI ethics principles referenced by Chapter 5-D, including human oversight, fairness, accountability, privacy, transparency, security, accessibility, and lifecycle governance. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- New Hampshire RSA Chapter 507-H — Expectation of Privacy — New Hampshire General Court. Supports: Current consumer-data privacy scope, definitions, rights, controller obligations, sensitive-data consent, universal opt-out mechanisms, exemptions, enforcement, and January 1, 2025 effective date. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- New Hampshire RSA 507-H:7 — Processor Responsibilities — New Hampshire General Court. Supports: Current processor assistance, contract contents, confidentiality, return or deletion, compliance evidence, subcontractor objection and flow-down, assessment, and operation-specific role provisions. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- New Hampshire RSA 507-H:8 — Heightened Risk of Harm — New Hampshire General Court. Supports: Current data-protection-assessment triggers and required benefit, risk, safeguards, context, relationship, and reasonable-expectation analysis for covered processing created after July 1, 2024. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- New Hampshire RSA 507:8-k — Solicitation of Children Through Responsive Generative Communication — New Hampshire General Court. Supports: Current January 1, 2026 civil-liability provision for specified owners and operators, its knowledge and intent elements, listed harmful conduct, enforcement and cure path, damages provision, and express service exceptions. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- New Hampshire RSA 359-C:20 — Notification of Security Breach Required — New Hampshire General Court. Supports: Current owner-or-licensee misuse determination and notice path, non-owner maintainer's immediate notification and cooperation duty, notice methods and contents, and consumer-reporting-agency threshold. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- New Hampshire RSA Chapter 420-P — Insurance Data Security Law — New Hampshire General Court. Supports: Current licensee-only security-program, third-party-provider, incident-response, prompt investigation, five-year cybersecurity-event record, conditional three-business-day commissioner notification, update, and provider-event provisions. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Artificial Intelligence Risk Management Framework — National Institute of Standards and Technology. Supports: Maintained voluntary methodology for governing, mapping, measuring, and managing AI risk across the lifecycle without treating the framework as proof of legal compliance. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Secure Software Development Framework — National Institute of Standards and Technology. Supports: Maintained secure-development methodology for protected environments, software provenance, release integrity, vulnerability response, and buyer-supplier evidence. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- IANA Time Zone Database — Internet Assigned Numbers Authority. Supports: Maintained time-zone identifiers and transition rules for calculating dated overlap between New Hampshire buyer cities and every proposed contributor city. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
- Directory of Intellectual Property Offices — World Intellectual Property Organization. Supports: Official destination-country intellectual-property office links for investigating contributor and assignment questions rather than assuming a New Hampshire contract resolves every jurisdiction. Direct source; independently sourced; commercial relationship: none. Verified 8/15/2026 by Outsourcing.ai Editorial Team. Accessed 8/15/2026.
Next scheduled review: September 30, 2026. Corrections: hello@outsourcing.ai.
