USD
United States
Fast to pilot, slow to procure, and unusually sensitive to security review.

US mid-market buyers move quickly from interest to a paid pilot and then hit a procurement and security review that European buyers often do not have.
Market notes
How buying works in the US market.
Pilots are normal and expected
A fixed-scope paid pilot is the standard way in. Buyers are comfortable spending to de-risk before committing, which suits an assessment-first model well.
Security review is the real gate
Mid-market and above will ask where data resides, who processes it, whether it trains a model, and what happens on breach. Having written answers before the question is asked shortens the cycle materially.
ROI framing is expected in the first conversation
US buyers generally want the business case earlier than European counterparts. Hours recovered and cost per transaction land better than capability descriptions.
Distributed operations raise the integration bar
Multi-state operations frequently run regional variations of the same process. Workflow mapping has to capture the variants rather than an idealised national process.
Readiness
What decides the design in United States.
The things that actually change when scoping a build here — ordered by whether they are routine, need scoping, or shape the architecture from day one.
- Paid pilot before commitmentStandard route in. Fixed scope, fixed price, measured against a baseline.Standard
- Security review packData residency, processing, training exclusion and breach handling, answered in writing before the question is asked.Needs scoping
- ROI framing in the first conversationHours recovered and cost per transaction, not capability descriptions.Standard
- State-level privacy obligationsVary by state. Residency, retention and consumer rights specified per deployment.Needs scoping
- Sector regime where it appliesHealthcare, financial services and education shape architecture more than general privacy law.Decides the design
- Regional process variantsMulti-state operations run variants of the same process. The map has to capture them.Needs scoping
Described in general terms to explain how it affects a build. Not legal advice — every engagement assumes you take your own.
Regulatory context
What shapes the design here.
Described in general terms to explain how it affects a build. It is not legal advice, and every engagement assumes you take your own.
State-level privacy law rather than one federal regime
Privacy obligations vary by state, with California among the most developed. The practical consequence is that data residency, retention and consumer rights handling need to be specified per deployment rather than assumed.
Sector regimes dominate where they apply
Healthcare, financial services and education carry their own obligations that generally matter more to a build than general privacy law. Where they apply, they shape the architecture from the first workshop.
Disclosure expectations are tightening
Requirements around telling people they are interacting with an automated system are becoming more common. We disclose by default, which keeps this a non-issue.
Sector emphasis
Where US demand concentrates.
- Real EstateInformation became free. Trust did not.
- Logistics & TransportEvery 'where is my shipment' call is margin you already priced away.
- Professional & Legal ServicesProductivity gains cannibalise revenue when you bill by the hour.
- E-commerce & RetailAn assistant may soon sit between you and your customer.
- Healthcare & ClinicsAdministrative load, not clinical capacity, is the binding constraint.
Engagement shape
How work typically runs here.
Typically: assessment, then a fixed-scope workflow sprint that doubles as the security review artefact, then broader rollout.
You know AI matters and you do not yet know where it would apply here.
Working in United States?
The assessment is the same wherever you are. What changes is how the build gets scoped around the constraints above.
Eleven questions, scored in your browser