The regulatory clock has been ticking for almost a decade, yet a startling number of enterprises have chosen not to hear it. Despite the passage of Kari’s Law and RAY BAUM’S Act, legislation designed to ensure direct access to emergency services and accurate location data from enterprise phone systems, industry data suggests that nearly 40 percent of organisations remain non-compliant.
For half a decade, the Federal Communications Commission (FCC) treated this gap with a degree of leniency, prioritising education over punishment. That era of benign neglect has abruptly concluded.
The transition is a fundamental change in how the US government views the enterprise's responsibility toward its workforce. The days of assuming that a legacy PBX or a sprawling cloud migration provides a shield against federal scrutiny are over. The Commission has signalled a hard pivot toward active policing, driven by a realization that voluntary adoption has stalled.
Lauren Kravetz, the former Chief of Staff at the FCC’s Public Safety and Homeland Security Bureau and current Vice President of Government Affairs at Intrado, offered a stark assessment of the current landscape to UC Today:
"If you want to call the last few years a grace period, then yes, I’d say we’re moving into a new era that could lead to enforcement investigations."
The implications for the C-suite are seismic. Compliance is no longer a box-ticking exercise for the telecom manager, but a critical governance issue that carries the weight of federal law and, uniquely, the potential for individual accountability.
- The Compliance Schism: Why 2026 is the Year of the ‘Two-Stack’ Enterprise
- Automate at Your Own Risk: Why Real-Time Compliance Can Fail
The End of the Honour System With Enterprise 911 Compliance
To grasp the urgency of the current moment, one must appreciate the legislative intent. Kari’s Law was born from tragedy in a hotel room, necessitating direct dialling for 911 without requiring a prefix. RAY BAUM’S Act followed, mandating that a "dispatchable location" be conveyed to emergency responders. These rules were complicated, rolling out with staggered implementation dates that allowed many organizations to procrastinate, citing technical hurdles or confusion.
However, the regulator's patience has evaporated. The catalyst for this renewed vigor is not a new law, but the failure of the market to adapt to the existing ones. "What’s changed is that the Commission was made aware that compliance rates are relatively low and, in their words, became 'concerned that awareness and compliance are uneven'," said Kravetz.
The FCC initially focused its outreach on the hospitality sector, the original context for Kari’s Law. However, as the mandate broadened to the broader enterprise, the message failed to penetrate. "Now that all elements of the rules have been in effect for a couple of years, the FCC is evaluating next steps to improve compliance," Kravetz noted.
"The guidance that the Public Safety and Homeland Security Bureau issued last summer is intended to ensure enterprises understand their obligations and to make sure that public safety officials are aware of and understand these obligations and can monitor what’s happening in their area."
This creates a pincer movement. The FCC is educating enterprises on what they must do, while simultaneously educating public safety answering points (PSAPs) on what they should expect and report if missing.
Travis Dahlgren, Senior Solution Engineer at Intrado, suggested to UC Today that the industry has fundamentally misread the room regarding the FCC’s tolerance. "From the FCC’s perspective, education and flexibility have not produced consistent results, so clearer guidance and stronger oversight became necessary," Dahlgren explained. "They’re also hearing more concerns from public safety agencies who are encountering poor location data in real emergencies."
"We think the message to enterprises is simple: the learning period is over, and enforcement is now part of the equation."
The 911 Liability Trap: When Technical Oversight Becomes Personal Risk in Enterprise Compliance
Perhaps the most chilling aspect of these statutes for IT and security leaders is the piercing of the corporate veil. In the realm of enterprise tech, fines are typically levied against the legal entity. The corporation writes a check, and the board moves on. However, the language in these specific public safety acts introduces a specter of personal liability that many CIOs and IT Directors have yet to fully comprehend.
Congress, in its drafting of the legislation, took an aggressive stance to prevent organizations from burying safety obligations in bureaucracy. Kravetz outlined:
"It’s a little unusual in the 911 context to see liability assigned to individuals rather than only the enterprises, but that’s the decision that Congress made."
"To ensure the safety of the public, Congress applied the obligations not only to the business engaged in 'manufacturing, importing, selling, leasing, installing, managing, or operating' an MLTS but also to the people involved, specifically the MLTS manager and installer," she added.




