The Claim Under Test
Nearly every AI vendor pitching security and alarm monitoring companies in 2026 leads with a number nobody outside the company has audited.A video-analytics vendor claims it filters out a specific share of false alarms. A remote-guarding platform promises a fixed percentage saved over on-site guards. A weapons-detection scanner claims it catches everything a metal detector would and more — and in at least one well-documented case, that exact category of claim became the subject of a federal enforcement action after the product missed a real weapon and repeatedly flagged harmless items instead.
Security and alarm monitoring is also a genuinely underappreciated category for how much an AI agent's overreach can cost, because the downstream action isn't a missed sale — it's a police or fire dispatch, or a live confrontation with a real person on camera. Get either wrong at scale, and the exposure isn't a bad review; it's a wrongful-dispatch complaint, a use-of-force incident triggered by bad information, or a liability claim tied to an AI system that confidently misread an ambiguous scene. This article ranks thirteen AI vendors and platforms in this category on what you can actually verify — published pricing, named integrations, current ownership, and what the product genuinely does — and treats the dispatch and confrontation decisions as their own dedicated section, because that is where a wrong vendor choice does real damage.
The most useful finding in this article may be the stat we could not confirm as current: a "$1.8 billion a year" cost of false alarms to U.S. police departments, traced to a single report published in 2002 and still repeated today as if it were fresh. We cover exactly how that figure ages out, and what a widely deployed AI weapons-detection vendor's own regulator found about its accuracy claims, in the sections below.
How We Ranked, and What We Refused to Rank On
We scored each vendor on four things you can re-check without taking anyone's word for it: whether it publishes real, dollar-amount pricing; what named integrations it lists on its own site; who currently owns or controls the company, checked against the vendor's own materials rather than assumed from an older article; and what the AI product actually does — agentic action (a system that verifies, classifies or communicates on its own) versus infrastructure a human reviews before it reaches anyone.
We explicitly refused to score anything nobody can substantiate with a disclosed methodology: false-alarm-reduction percentages, guard-cost-savings ranges, or a per-incident dollar figure with no named sample. The table below names four specific claims we found in this category's marketing and states plainly what we print instead.
| The claim | Where it comes from | What we print instead |
|---|---|---|
| "$1.8 billion a year" in false-alarm costs to U.S. police, from "36 million" false alarms annually | A single report published in 2002 by the federal problem-oriented-policing program, still cited today with no newer authoritative national estimate to replace it | The figure named as decades-old and not repeated as a current cost; the underlying rate (LAPD: 90%+ of monthly alarm calls false) cited separately, since that part is well corroborated |
| "86% of users see ROI from video analytics within one year" | Vendor-blog-sourced claim with no disclosed sample or methodology | Attributed to vendor marketing only, not printed as a general or verified fact |
| "$50,000–$500,000 saved per prevented major security event" | Vendor ROI-calculator marketing input with no disclosed basis for the range | Named as a vendor input, not a verified savings figure |
| "AI-augmented remote guarding cuts security costs by 30–70%" (and Eagle Eye's own "50–90%" launch-announcement figure for its Remote Video Monitoring product) | Repeated across guarding-industry marketing blogs and vendor launch materials, with no consistent independent study or disclosed site-profile methodology behind either range | Both ranges attributed by name to marketing, with a suggestion to compare your own guard-hours cost against a written, site-scoped vendor quote instead |
A visible methodology note, since this article ranks vendors: everything above was checked as of 17 September 2026, against each vendor's own site, a press release naming the vendor directly, an FTC or DHS filing, or trade coverage from outlets including SDM Magazine, Security Info Watch and Security Systems News, attributed as such. Where we could only find a figure via a vendor's own press materials with no independent corroboration, we say so explicitly rather than presenting it as a verified fact. You can re-check every claim in this article the same way: visit the vendor's own pricing and product pages, confirm a company's current ownership via its own newsroom or a dated acquisition announcement, and check your own state's alarm-company licensing statute directly rather than trusting any AI-generated summary of it, including ours.
What the Data Actually Shows
The false-alarm rate itself is not in serious dispute, even though the headline cost figure attached to it is stale. LAPD's own Alarm Section materials state that officers handle roughly 6,000 to 7,000 alarm calls a month, and more than 90% turn out to be false — a share consistent with figures cited across the monitoring industry, and the reason the City of Los Angeles revised its alarm ordinance to stop responding to unpermitted or repeat-false alarms free of charge.
What changed in Los Angeles specifically, effective 2026
- A flat $260 false-alarm fee: took effect for alarms occurring on or after May 4, 2026, replacing the prior fee structure, per the LA Office of Finance's own Alarm Permits and Alarm Ordinance FAQ.
- Escalating penalty assessments for repeat offenders: a $50 penalty on the second false alarm within a rolling 365 days, increasing by $50 for each additional false alarm in that same window.
- A verified Burglary Alarm Policy: requiring verification after two false activations within a rolling year, and a once-per-365-day fee waiver available through an Alarm School course.
Nationally, the picture is more structural than a single dollar figure can capture. The Monitoring Association's 2024 ANSI/TMA-AVS-01 standard replaced the industry's old binary alarm signal (intrusion or not) with a five-tier classification, specifically so a monitoring center can hand a dispatcher a graded confidence level rather than one flat flag — and UL now certifies monitoring centers against that standard directly. Separately, cities that have adopted verified-response policies report real, measured outcomes: a peer-reviewed 2020 study in the International Review of Law and Economics found that Salt Lake City's verified-response policy, adopted in 2000, was associated with an 87% annual reduction in police alarm-response calls and a separate 26% reduction in burglaries, while also freeing dispatcher and officer time for other calls. That is a specific, dated, independently published finding — a meaningfully different kind of evidence than a vendor's own ROI calculator.
The Comparison Table
Checked 17 September 2026, against each vendor's own site, help center, or a press release naming it directly. "Not publicly disclosed" means pricing sits behind a dealer network, an authorized reseller, or a sales conversation, not that no such figure exists.
| Vendor (checked 2026-09-17) | What it actually is | Published pricing | Named integrations on the vendor's own site | Ownership of record |
|---|---|---|---|---|
| 1. Alarm.com | Unified cloud platform (video, access control, automation, energy) for residential and commercial properties; 2026 AI additions include AID (AI-generated verbal deterrence warnings) and AI Access Assist (natural-language access-control administration) | Not publicly disclosed; sold through Alarm.com's dealer network | Broad native ecosystem across its own hardware and dealer integrations | Publicly traded, NASDAQ: ALRM; surpassed $1B in annual revenue per its own 2026 reporting |
| 2. Deep Sentinel | AI-detection-plus-live-guard remote video monitoring; an AI system flags likely threats, and a live human guard intervenes by two-way audio before police are ever called | Consumer plans published on its own site; commercial/business pricing sales-gated | Runs on its own proprietary camera hardware rather than third-party cameras | Private, independent; raised $15M in a Series B round (Egis Capital Partners) in 2025 |
| 3. Actuate | AI video-analytics layer that plugs into a central station's existing monitoring software to verify a burglar alarm — scanning cameras for an actual intruder — before a human operator ever sees it | Not publicly disclosed | Named integration partners include Bold Group's Manitou and Immix's AutoPatrol | Private, independent — originally launched as Aegis AI, rebranded to Actuate in October 2019; raised $11.5M in a round led by Gray Line Partners |
| 4. Noonlight | API-based "verified emergency response" layer: an AI system reviews an incoming signal and, if it can't rule out a real emergency, escalates to Noonlight's own trained human dispatch agents | Not publicly disclosed; priced by alarm volume rather than agent hours | Powers third-party hardware brands' monitoring, including an announced ("coming soon") integration with Ubiquiti's UniFi Protect | Private, independent |
| 5. Rhombus Systems | Unified cloud platform (cameras, access control, sensors, alarms) with built-in 24/7 professional alarm monitoring dispatched by TMA Five-Diamond-certified human dispatchers; AI is used to cut nuisance alerts before they ever reach a dispatcher | Not publicly disclosed; licensed per location, sold through authorized resellers | Native camera, access-control and sensor ecosystem | Private, independent |
| 6. Verkada | Enterprise unified physical-security platform (video, access control, alarms, intercoms) with AI-powered video alarm triage and 24/7 professional monitoring | Not publicly disclosed; enterprise, sales-led | Broad native ecosystem across its own hardware line | Private, independent — paid a $2.95M FTC settlement in 2024 over 2020–21 data-security failures that exposed roughly 150,000 live camera feeds |
| 7. Ambient.ai | Enterprise threat-detection platform built around a vision-language model ("Ambient Pulsar") that reasons over existing camera and access-control feeds in real time, flagging genuine threats — including brandished firearms — among 150+ signal types | Not publicly disclosed; enterprise, sales-led | Layers onto a customer's existing cameras and access-control hardware rather than requiring its own | Private, independent — founded 2016 by two Stanford AI researchers |
| 8. ZeroEyes | AI gun-detection platform layered onto existing security cameras; a detected firearm image routes to ZeroEyes' own 24/7 human Operations Center — staffed by military and law-enforcement veterans — for human confirmation before police are alerted | Not publicly disclosed | Integrates with a customer's existing camera infrastructure; deployed across K-12 districts, universities and Fortune 500 campuses | Private, independent — first AI-based gun-detection technology to receive full DHS SAFETY Act Designation (approved Sept. 30, 2024, expiring Sept. 29, 2029) |
| 9. Bold Group (Manitou) | Long-running central-station alarm-monitoring automation software; AI capability comes through named third-party partners (Actuate, Immix's AutoPatrol) plugged into the Manitou workflow rather than an in-house Bold-built model | Not publicly disclosed | Named integration partners: Actuate, Immix | Owned by EverCommerce (NASDAQ: EVCM) since the 2018–19 merger of Bold Technologies and Perennial Software, plus its SIMS and SGS acquisitions |
| 10. Immix | Video-centric central-station and security-operations-center monitoring software; its AutoPatrol module adds AI-driven proactive video monitoring, available with Actuate as an AI-provider option | Not publicly disclosed | Names Actuate and Eagle Eye Networks as integration partners on its own site | Acquired by Graham Partners in 2026; previously owned by Norland Capital (from Feb. 2021) after splitting from SureView Systems in March 2020 |
| 11. Calipsa | Cloud-based video false-alarm-reduction analytics that plug into a central station's existing camera feeds, filtering out nuisance alerts before a human operator ever sees them — the company states it can remove more than 90% of false alarms without new hardware | Not publicly disclosed | Integrates with third-party VMS and central-station software; deployed via monitoring-center partners | Acquired by Motorola Solutions in April 2022; no longer an independent company |
| 12. Eagle Eye Networks | Camera-agnostic cloud VMS with AI built directly into the platform (Precision Person & Vehicle Detection, gun detection with "triple-layer" AI verification, automatic license-plate reading); launched Eagle Eye Remote Video Monitoring, combining AI analytics with professional monitoring agents, on October 21, 2025 | Not publicly disclosed | Names Immix among integration partners; ONVIF-compliant, works with most existing IP cameras | Private, independent; founded 2012 |
| 13. Evolv Technologies | Publicly traded AI weapon-detection scanner line, widely deployed in K-12 schools and public venues; included here as a deliberate cautionary entry, not a recommendation | Not publicly disclosed | Standalone walk-through scanner hardware line, not a software layer on existing cameras | Publicly traded, NASDAQ: EVLV; settled an FTC complaint in November 2024 over deceptive claims about its scanners' weapon-detection accuracy |
The Thirteen, in Order
1. Alarm.com.The largest, most diversified platform in this list by revenue — publicly traded (NASDAQ: ALRM) and reporting more than $1 billion in annual revenue as of its 2026 disclosures. Its newest AI features, previewed at ISC West 2026, are genuinely agentic in different directions: AI Access Assist lets an administrator manage users and credentials with natural-language commands, while AID generates AI verbal warnings directed at a person on camera — the exact feature this article treats as one of its two bright lines later on.
2. Deep Sentinel.A deliberately hybrid model: AI flags likely threats across its camera network, and a live human guard reviews the feed and intervenes by two-way audio before police are ever called. It's also the one vendor in this roster with genuinely published consumer pricing, and it raised a $15M Series B (led by Egis Capital Partners) in 2025 as an independent company.
3. Actuate.Not a monitoring platform itself — an AI video-verification layer that plugs into a central station's existing software (named partners include Bold Group's Manitou and Immix's AutoPatrol) to scan cameras for an actual intruder before a human operator sees the alarm at all. Worth knowing before you assume it's a new entrant: it launched as Aegis AI and rebranded to Actuate in October 2019, and has raised $11.5M in funding led by Gray Line Partners.
4. Noonlight.An API-first "verified emergency response" company rather than a hardware or monitoring-software vendor: its AI reviews an incoming signal, and where it can't confidently rule out a real emergency, the case escalates to Noonlight's own trained human dispatch team. It licenses this capability into third-party hardware ecosystems, including an announced integration with Ubiquiti's UniFi Protect.
5. Rhombus Systems.A unified platform — cameras, access control, sensors and alarms in one console — whose professional alarm monitoring is dispatched specifically by TMA Five-Diamond-certified human dispatchers, with AI used to reduce nuisance alerts before a dispatcher ever reviews them. That combination (AI filtering plus a named, industry-certified human dispatch standard) is exactly the pairing this article argues every vendor in this category should be moving toward.
6. Verkada.A large, enterprise-focused unified security platform with AI-powered video alarm triage. Its inclusion here comes with an asterisk worth taking seriously: Verkada paid a $2.95M FTC settlement in 2024 over 2020–21 data-security failures that let hackers access roughly 150,000 live camera feeds, including footage from psychiatric hospitals and women's clinics. A vendor holding your live camera and alarm data is itself a target, and that history belongs in your evaluation, not a separate cybersecurity conversation.
7. Ambient.ai.Built around a purpose-trained vision-language model ("Ambient Pulsar") that reasons over a customer's existing camera and access-control feeds in real time, rather than requiring new hardware. Founded in 2016 by two Stanford AI researchers, it markets itself on breadth of signal — more than 150 threat types, including brandished firearms — layered onto infrastructure a large enterprise already owns.
8. ZeroEyes.The one AI gun-detection vendor in this roster built around a hard human-verification step by design: a detected firearm image routes to ZeroEyes' own 24/7 Operations Center, staffed by military and law-enforcement veterans, for human confirmation before police are alerted. It's also the first AI-based gun-detection technology to receive full DHS SAFETY Act Designation, a liability protection running from September 2024 through September 2029 — a real, verifiable government designation, though one that protects against terrorism-related liability specifically rather than certifying general detection accuracy (see the FAQ on this distinction).
9. Bold Group (Manitou).The incumbent central-station automation platform in this list, and a useful lesson in how consolidated this industry's software has become: EverCommerce (NASDAQ: EVCM) acquired both Bold Technologies and Perennial Software in 2018, merged them into Bold Group in 2019, and folded in SIMS and SGS afterward. Manitou's own AI capability isn't an in-house model — it ships through named partners, principally Actuate and Immix.
10. Immix.A video-centric monitoring platform for central stations and security operations centers, whose AutoPatrol module adds AI-driven proactive video review. Its ownership has moved twice in five years — from a 2020 split with SureView Systems, to Norland Capital in 2021, to Graham Partners in 2026 — which is worth tracking directly with the company rather than assuming an older writeup still describes who's behind it.
11. Calipsa.Cloud-based video false-alarm-reduction analytics, acquired by Motorola Solutions in April 2022 and no longer independent. The company's own claim — filtering out more than 90% of false alarms from existing IP camera feeds with no new hardware — is a real, specific, self-reported figure; we cite it as such, attributed to Calipsa, not as an independently audited industry benchmark.
12. Eagle Eye Networks.A camera-agnostic cloud VMS with AI built directly into the core platform — person and vehicle detection, gun detection with layered AI verification, automatic license-plate reading — that launched a combined AI-plus-professional-monitoring product, Eagle Eye Remote Video Monitoring, on October 21, 2025. Its own launch materials claim 50–90% savings versus on-site guard costs; we treat that the same way we treat every other vendor-published savings range in this article — a marketing input, not an audited number.
13. Evolv Technologies.The deliberate cautionary entry, included the way the honest version of this ranking has to include it. Evolv (NASDAQ: EVLV) is one of the most widely deployed AI weapon-detection vendors in U.S. schools and venues, and in November 2024 the FTC settled a complaint alleging the company deceptively advertised that its scanners would detect all weapons while ignoring harmless items — following a documented failure to detect a knife later used in a stabbing, and a separately reported false positive at a Maryland high school where a bag of chips was flagged as a weapon. It is not on this list as a recommendation; it is on this list because a buyer doing real diligence in this category needs to know that fact, and an honest ranking doesn't leave it out because it's inconvenient.
Licensing, Standards and Local Ordinances
Three layers govern almost everything a security or alarm-monitoring AI agent does once it moves past scheduling and into anything resembling a verification or dispatch decision, and all three predate this category's AI products by years or decades.
State alarm-company licensing.California requires an Alarm Company Operator (ACO) license from the Bureau of Security and Investigative Services for any company that installs, maintains, monitors or services alarm systems, under Business and Professions Code §7590 et seq. — a criminal background check through the California DOJ and FBI, roughly 4,000 hours of documented paid experience, and a licensing exam covering state law, weapons law and power-to-arrest are all required of the company and its people. None of that requirement moves because an AI system now handles most of the signal-triage volume a human used to; the license and the accountability it carries stay with the licensed company and its registered agents.
| Question | What the law or standard requires | Who may act | Practical control |
|---|---|---|---|
| Can an AI system alone confirm an alarm signal as real and request police dispatch? | ANSI/TMA-AVS-01's five-tier classification and city verified-response policies both require a defined confirmation step (video, audio, panic activation or credentialed human judgment) before a dispatch request is treated as verified | A trained, credentialed human dispatcher confirms; the AI system triages, scores and prioritizes what that dispatcher sees first | Hard-code a human-confirmation gate before any AI classification can trigger a public-safety dispatch request; log the confirming dispatcher's identity on every request |
| Does the company monitoring the alarm need a state license, regardless of how much AI does the work? | California's Alarm Company Operator license (Bus. & Prof. Code §7590 et seq., administered by BSIS) attaches to the company and its registered alarm agents, with background checks, ~4,000 hours of documented experience and an exam required | The licensed company and its registered individual agents are accountable, not the software vendor | Maintain and audit ACO (or the equivalent in every other state you operate in) licensing status on a recurring compliance calendar, independent of AI adoption |
| Who is accountable if an AI-generated alarm classification or dispatch recommendation is wrong? | The licensed monitoring company and its accountable dispatcher of record, regardless of which vendor's AI produced the underlying classification | The human dispatcher who confirms (or should have confirmed) the classification before acting on it | Log every AI-generated classification alongside the human reviewer who approved or overrode it before it becomes a dispatch record |
Industry classification and certification standards. ANSI/TMA-AVS-01, published by The Monitoring Association and now the basis for a UL certification program, replaced the old binary intrusion-or-not alarm signal with a five-tier classification, giving a dispatcher a graded confidence level instead of one flat flag. Underneath that sits UL 827 (criteria for central-station alarm services themselves) and UL 1981 (the automation systems inside a central station, including operator-duress-signal requirements added in a 2023 revision — a hidden signal a coerced operator can send, which any AI layer added to a central station needs to preserve, not route around). TMA's separate Five Diamond designation requires 100% of a monitoring center's operators to hold TMA certification, re-earned annually — a human-training regime an AI system doesn't satisfy on a company's behalf, however much of the triage work it performs. If your facilities-management operation contracts out monitoring, ask directly whether the central station behind your AI-enabled monitoring plan currently holds Five Diamond and UL 827/1981 status, not just whether its AI vendor sounds impressive.
Local ordinances and verified-response policy add a third, geography-dependent layer.Los Angeles now charges a flat $260 false-alarm response fee for alarms on or after May 4, 2026, with escalating $50 penalty assessments for repeat false alarms within a rolling year, and requires verification after two false activations. Separately, cities that have adopted verified-response policies — Salt Lake City's dates to 2000 — won't dispatch officers to an unverified alarm at all, regardless of what a monitoring center's software says. Neither rule cares whether the underlying classification came from an AI system or a person; both attach to the service address and the jurisdiction, not to the software that produced the signal.
| Question | What it requires | Where it applies | Practical control |
|---|---|---|---|
| Does a false alarm carry a financial penalty? | Los Angeles charges a $260 false-alarm response fee (effective for alarms on or after May 4, 2026), with escalating $50 penalty assessments for repeat false alarms within a rolling 365 days | City- and county-specific; LA's ordinance is one example among many with their own fee schedules | Keep an automated fee-schedule lookup tied to the service address's jurisdiction, refreshed on a recurring calendar rather than hard-coded once at build time |
| Will police even respond to an unverified alarm? | Verified-response policies (e.g., Salt Lake City's, adopted in 2000) require video, audio, a panic activation or eyewitness confirmation before officers are dispatched at all | City-specific; a growing number of jurisdictions have adopted some form of verified response | Confirm your monitored jurisdictions' verified-response requirements before assuming any alarm signal alone will produce a dispatch |
| Does a central station's monitoring software itself need to meet a technical standard? | UL 827 sets criteria for central-station alarm services (facility, response time, redundancy); UL 1981 covers the automation systems inside the central station specifically, including operator-duress-signal requirements added in a 2023 revision | Applies to the central station's own operations and technology, largely independent of which state licenses the company | Confirm a central station (in-house or outsourced) holds current UL 827/1981 listing, and that any AI layer added doesn't compromise operator-duress-signal functionality |
| Can an AI voice or chat agent verify a customer's identity before disarming monitoring or changing an authorized-contact list? | No specific federal statute, but this is a well-known social-engineering attack surface in the alarm industry — a caller claiming authority ("I'm the property manager") is a common vector for getting monitoring disabled or a code changed | The agent may gather the request, but a hard identity-verification step (not just a request phrased with apparent authority) should gate any account or monitoring-state change | Require a pre-established verification method (a PIN, a callback to a number on file) before any AI agent executes a monitoring-state or contact-list change — never accept an unauthenticated request at face value, however confidently it's phrased |
The Two Bright Lines: Dispatch and Confrontation
If this article has two sentences worth remembering, they are these: an AI agent should never be the sole, final basis for requesting a police or fire dispatch, and an AI agent should never be allowed to confront a person on camera with open-ended, unscripted language. Both are places where a fast, automated system is structurally the wrong final actor, because both sit on top of frameworks — licensing regimes, verified-response policies, an industry validation standard — built specifically to put a graded, accountable human decision between a signal and a real-world consequence.
Dispatch confirmation.An AI video-verification system is well suited to pulling and scoring the camera feed the instant a signal fires, ranking it against a monitoring center's five-tier classification, and surfacing the highest-confidence cases first. It is badly suited to being the system whose classification alone triggers an armed police response, because that decision is exactly what ANSI/TMA-AVS-01 and city verified-response policies were built to gate behind a trained human's confirmation — and because the licensed monitoring company, not the AI vendor, is the one legally accountable under regimes like California's ACO license for what its dispatch decisions produce.
Confrontation.A feature like Alarm.com's AID, which generates AI verbal warnings directed at a person on camera, is reacting to a fundamentally untrusted and ambiguous input: a real human being, in a real situation, whose intent the system cannot actually know. A resident who forgot their key, a delivery driver, and a genuine intruder can look identical to a camera in the first several seconds. An AI system that treats its own read of that scene as confident enough to escalate its language, threaten consequences, or improvise beyond a fixed script is exactly the kind of unsolved problem this article's framing keeps returning to — not because the underlying detection is necessarily bad, but because acting on an ambiguous read with unbounded language is a liability surface no vendor has closed. Treat any AI verbal-deterrence capability as blast-radius reduction: a fixed, reviewed, narrow script, logged every time it fires, never an open license to improvise.
The design rule for both is the same one that shows up across every regulated vertical we've covered: automation for the reversible and low-consequence steps — scoring, triage, drafting — and a human decision at the point where the action becomes legally or physically consequential. That is a credential-scoping problem as much as a policy one: the agent's technical ability to finalize a dispatch request or improvise a confrontation shouldn't exist as a capability at all, rather than existing and being governed by a policy document nobody re-checks under time pressure.
A Worked Example: When Off-the-Shelf Beats a Custom Build
Consider a single-site alarm-monitoring reseller operating under one state's Alarm Company Operator license, dispatching through a third-party central station that already holds Five Diamond and UL 827/1981 status. Its call volume is mostly routine — billing questions, service scheduling, the occasional false-alarm fee dispute — and its actual signal verification already runs through its central station's existing AI-plus-human process. This is squarely the market Rhombus, Noonlight or a comparable platform's published dealer program is built for: pay for an existing, professionally monitored platform rather than build custom verification infrastructure you don't need, since the hard part — TMA-AVS-01-aligned classification, credentialed human dispatch — is already someone else's solved problem.
Now consider a regional monitoring company running its own central station across three states, each with its own alarm-company licensing threshold, plus a growing base of commercial clients asking for AI-generated on-camera warnings as a deterrence feature before they'll sign. That is precisely the point where off-the-shelf platforms start to strain: a verbal-deterrence script that's appropriately scoped and legally reviewed for one client's parking structure is not automatically appropriate for another client's retail storefront with different foot traffic and different risk tolerance, and a licensing compliance calendar spanning three states' different renewal cycles is exactly the kind of coordination work generic monitoring software wasn't built to track. That is where Frenchy Digital's discovery-and-audit engagement ($9k–$22k, 2–4 weeks) earns its cost: mapping which workflows genuinely need multi-state consistency, which off-the-shelf pieces can stay as they are, and where a purpose-built AI agent with a hard-coded dispatch-confirmation gate and a locked, per-client verbal-warning script is worth the higher cost of a single-workflow build ($28k–$70k, 4–9 weeks).
This is deliberately not a projected-savings scenario — we are not going to invent a guard-labor-avoided dollar figure, for the same reason we refused the industry's unsourced "30–70%" cost-reduction range earlier in this article. The honest arithmetic here is about license count, jurisdiction count, and published or dealer-quoted pricing, all of which you can verify yourself, not about a savings outcome nobody has independently measured.
The Human-in-the-Loop Boundary
The table below sets out, action by action, what a security or alarm-monitoring AI agent can reasonably do alone and what it should never do without a human — the dispatch and confrontation boundaries from the section above are two rows among several with the same underlying logic: automate the reversible and low-consequence, escalate anything legally or physically attributable to a licensed company or gated by a specific standard.
| Action | Who may do it | Why the line sits here | Control that makes it safe |
|---|---|---|---|
| Answer questions about service plans, pricing tiers and coverage area | Agent alone | Retrieval from a source the operator controls, with no open-ended commitment | Single source of truth for pricing and coverage; log the record version behind every answer |
| Schedule or reschedule an installation or service appointment | Agent alone, with a confirmation text or email | Reversible, low-consequence, and the customer has an easy correction path | Confirmation on every booking; nightly diff against the actual technician schedule |
| Triage an incoming alarm signal (pull video/audio, apply an initial classification) | Agent alone, escalating high-weight or ambiguous signals (glass break, a duress code, a panic-button activation) for priority human review | Gathering facts and scoring confidence is not the same as confirming an emergency | Map every AI classification to the monitoring center's five-tier (or equivalent) scale; log every escalation and every signal that wasn't escalated |
| Take a monitoring-fee payment over the phone | Agent alone, using DTMF masking or an equivalent | Routine and low-risk when the payment flow keeps raw card data out of the agent entirely | Verify DTMF masking (or equivalent) in writing; never allow the agent to accept a spoken card number |
| Confirm an alarm signal as real and request a police or fire dispatch | Never the agent alone | TMA-AVS-01, verified-response policies and state alarm-company licensing regimes all put this judgment with a credentialed human dispatcher | Hard-code a human-confirmation gate before any dispatch request leaves the monitoring center |
| Issue a live verbal warning to a person on camera | Agent may issue a narrowly scripted, pre-approved warning only | The "input" is a real, ambiguous person in a live situation — never an autonomous, open-ended confrontation | Fix the warning script in advance, log every instance it fires, and route anything outside the script to a human operator |
| Disarm monitoring, or change a contact/authorized-user list, on a phone or chat request | Never the agent alone without a pre-established identity-verification step | A known social-engineering attack surface in this industry — a confident-sounding claim of authority is not identity | Require a PIN or callback-to-number-on-file before executing any monitoring-state or contact-list change |
| Respond to a negative online review | Agent drafts, a human sends | Review text is untrusted external content, and a bad automated reply outlives every good one | Draft state only inside your own system; no send credential in any session that reads external review text |
| Waive a small late fee within a pre-approved cap | Agent alone, within a defined dollar cap | Bounded financial exposure the operator has already accepted as policy | Cap the waiver amount in the system itself; log every waiver for manager review |
On the response-time point specifically: a triage agent that takes too long to score an incoming signal erodes exactly the speed advantage vendors sell it on, unverified industry-wide savings figures aside. If you're evaluating how quickly a candidate agent actually classifies a signal under real load rather than in a demo, our guide to AI agent latency engineering covers the streaming and routing questions worth putting to a vendor directly, and our guide to AI agent evaluation and observability covers how to actually measure a classification agent's false-positive and false-negative rate yourself, rather than accepting a vendor's self-reported number the way Evolv's customers reportedly did before the FTC stepped in.
What Breaks First
Every one of these failure modes has a real precedent somewhere in the research behind this article — a consolidating vendor whose roadmap shifted after acquisition, a widely deployed product whose own regulator found its accuracy claims unsupported, a licensing rule that predates every AI product in this category by decades. Instrument for these before you need to.
| Failure mode | How you find out | Detection signal to instrument | Rollback |
|---|---|---|---|
| A vendor acquisition or ownership change quietly redirects a product's roadmap or support quality | An integration degrades with no release note, as could plausibly follow Immix's two ownership changes since 2021 or Calipsa's folding into Motorola Solutions' much larger portfolio | Track every vendor's current ownership and changelog on a recurring calendar, not just at signing | Keep an exportable record of alarm signals, video clips and dispatch logs so switching cost stays bounded |
| An AI verbal-deterrence agent escalates language or wrongly confronts a resident or visitor | A customer complaint, a safety incident, or a liability claim | Log every AID-style escalation and audit a transcript sample for language outside the fixed script | Revoke autonomous confrontation authority immediately; route all verbal warnings through the fixed, pre-approved script only |
| An AI signal-classification system's false-positive or false-negative rate has never been independently audited | The Evolv precedent: the FTC found the company's own accuracy claims unsupported, following a real documented miss (an undetected knife) and a well-publicized false positive (chips flagged as a weapon) | Require a vendor to produce a third-party accuracy audit, not a self-reported detection rate, before it gates a public-safety-relevant decision | Require human dispatcher confirmation before any AI classification alone can trigger a public-safety response |
| Social engineering through a support channel ("I'm the property manager, disarm monitoring for unit 4B") | An unauthorized monitoring change, or a break-in following one | Alert on every monitoring-state or contact-list change made without a completed identity-verification step | Revoke the agent's write-privilege for account changes from any unauthenticated session; this is a blast-radius control, not a detection one — treat unverified requests as untrusted input by default |
| A state licensing lapse (an expired Alarm Company Operator license, or an unregistered alarm agent) goes unnoticed as AI displaces human headcount | A regulatory audit, a denied insurance claim, or a licensing-board inquiry | A recurring compliance calendar tied to every state and county the company monitors alarms in | Pause monitoring operations in the affected jurisdiction until the license or registration is current again |
| A false-alarm fee or ordinance update (like LA's May 2026 fee change) isn't reflected in a customer-facing AI billing or scheduling agent | A billing dispute, or an under- or over-charged customer | A recurring jurisdiction-fee audit tied to every service address on file | Pause automated fee assessment in the affected jurisdiction until the agent's rule set is updated and re-verified |
On the social-engineering row specifically: a customer-facing AI agent that can disarm monitoring or change a contact list is only as safe as its identity-verification step, and a confidently worded request claiming authority is not the same thing as a verified identity. Treat any unauthenticated request to change a security-relevant setting as untrusted input by default — the same posture our guide to prompt injection and the OWASP LLM Top 10 recommends for any text an AI agent didn't generate itself, and our guide to AI agent memory architecture covers how long a monitoring agent should actually retain video clips, transcripts and dispatch logs before that retention becomes a liability rather than an asset.
Cost and Timeline
| Engagement | Range | Timeline | What it covers in a security/alarm-monitoring context |
|---|---|---|---|
| Discovery + workflow audit | $9k–$22k | 2–4 weeks | A signal and dispatch-volume baseline from your own monitoring logs, a licensing compliance review across every state and county you operate in, a TMA-AVS-01/Five Diamond gap check, and a vendor shortlist with the RFP questions we'd put in writing |
| Single-workflow agent | $28k–$70k | 4–9 weeks | One workflow end to end — customer scheduling and triage, or PCI-compliant phone billing — with hard-coded escalation for the dispatch-confirmation and verbal-warning bright lines |
| Multi-workflow platform with system integration | $70k–$180k | 9–16 weeks | Several workflows across your monitoring software, billing platform and account-change verification, jurisdiction-aware licensing and false-alarm-fee logic, a golden-set regression suite, and an owner-facing reporting pack |
| Enterprise / multi-state / regulated build | $180k–$420k+ | 14–24 weeks | Multi-state rollout with per-jurisdiction licensing and fee-rule versioning, full audit logging with human-dispatcher attribution on every police or fire dispatch decision, and a documentation package your counsel and insurer can review |
Senior-led work runs $150–$225 per hour, retainers run $2,500–$9,500 per month, every build carries a 30-day post-launch warranty, and full source-code and IP ownership transfers to you. We return a fixed-price phased proposal within 5 business days of a discovery call. If an existing dealer-network platform already covers your workflow, we will tell you so rather than propose a custom build you don't need — the honest answer for a single-site monitoring reseller is very often "buy an existing platform like Rhombus's or Noonlight's," not "hire an agency." If your operation runs on a legacy central-station platform that doesn't expose a clean API for the AI verification layer you want to add, our guide to modernizing legacy systems for AI agents covers what that integration work actually looks like before you commit to a build.
Red Flags When Evaluating a Vendor
- No disclosed accuracy audit behind a weapon or threat-detection claim: the Evolv precedent exists precisely because a vendor's own accuracy claims went unaudited until a regulator stepped in; ask for a third-party test, not a self-reported detection rate.
- An AI system that can independently trigger a police or fire dispatch with no named human confirmation step: if a vendor can't describe exactly who confirms a classification before it becomes a dispatch request, that's a design gap, not a workflow detail.
- An AI verbal-deterrence feature with no fixed, reviewed script: open-ended "confrontation" language aimed at a real person on camera is a liability surface, not a differentiator.
- No documented identity-verification step before an AI agent can disarm monitoring or change a contact list: a confidently phrased request is not the same thing as a verified identity — this is a well-known social-engineering vector in this industry.
- Outdated ownership information in a vendor's own marketing: a vendor's site that doesn't reflect a recent acquisition (its own, a partner's, or a competitor's) is a signal its content isn't kept current — ask directly about current ownership before signing.
- Unsourced false-alarm-reduction or guard-cost-savings percentages presented as neutral fact: any vendor citing a specific performance number with no disclosed methodology is asking you to trust marketing as measurement.
- No named DTMF-masking or equivalent for phone payments: if a vendor's AI agent takes monitoring-fee payments and can't describe, specifically, how it keeps raw card data out of its own audio and transcripts, that's a PCI compliance gap, not a detail to sort out later.
- No visible state alarm-company licensing, or a vendor that never asks which states and counties you're licensed in: a company's license and accountability don't transfer to software, however much of the verification work that software performs.
Limitations and What We Could Not Verify
Exact current pricing for eleven of the thirteen vendors in this roster is gated behind a dealer network, an authorized reseller, or a sales conversation, and we did not estimate a number on any vendor's behalf. We did not independently test any vendor's detection accuracy ourselves; every functional description in this article comes from the vendor's own published materials, help-center documentation, press coverage naming the vendor directly, or a regulatory filing (the FTC's complaints against Evolv and Verkada, and DHS's SAFETY Act designation for ZeroEyes), checked as of 17 September 2026.
This article discusses California's Alarm Company Operator licensing regime, Los Angeles's alarm ordinance and false-alarm fee schedule, and Salt Lake City's verified-response policy as illustrations of a real risk category; it is not a fifty-state survey. Alarm-company licensing, false-alarm fee schedules, verified-response adoption and central-station certification requirements all vary by state, county and sometimes municipality. Treat every regulatory citation here as a starting point for your own counsel and your jurisdiction's specific statute or ordinance, not a substitute for either.
Want an Honest Read on Your Security or Alarm-Monitoring AI Shortlist?
Book a free 60-minute discovery call. You leave with a signal-volume baseline from your own data, a state licensing and dispatch-policy compliance review, and a fixed-price phased proposal within 5 business days.
1517 S Bentley Ave Unit 204, Los Angeles CA 90025
Frequently Asked Questions
Sources & References
- 1Federal Trade Commission — "FTC Takes Action Against Evolv Technologies for Deceiving Users About Its AI-Powered Security Screening"↗
- 2Federal Trade Commission — "FTC Takes Action Against Security Camera Firm Verkada Over Charges It Failed to Secure Videos, Other Personal Data"↗
- 3Electronic Frontier Foundation — "FTC Rightfully Acts Against So-Called 'AI Weapon Detection' Company Evolv"↗
- 4CBS News Baltimore — "A.I. gun detection false alarm at school has Baltimore County leaders calling for review"↗
- 5The Monitoring Association — ANSI/TMA-AVS-01 Alarm Validation Scoring Standard↗
- 6The Monitoring Association — TMA-AVS-01-2024 Revision 2 (PDF)↗
- 7The Monitoring Association — Five Diamond Designation Program↗
- 8UL Standards & Engagement — UL 827, Central-Station Alarm Services↗
- 9UL Standards & Engagement — UL 1981, Central-Station Automation Systems↗
- 10International Review of Law and Economics — "Burglary Reduction and Improved Police Performance Through Private Alarm Response" (2020)↗
- 11LAPD Online — Alarm Section↗
- 12City of Los Angeles Office of Finance — Alarm Permits and Alarm Ordinance FAQs↗
- 13California Bureau of Security and Investigative Services — Alarm Company Act Fact Sheet↗
- 14Justia — California Business and Professions Code § 7590.2 (Alarm Companies)↗
- 15PR Newswire — "ZeroEyes Achieves Full SAFETY Act Designation for AI-Based Gun Detection and Intelligent Situational Awareness Platform"↗
- 16U.S. Department of Homeland Security — SAFETY Act Program↗
- 17Motorola Solutions Newsroom — "Motorola Solutions Acquires Calipsa"↗
- 18PR Newswire — "Actuate Secures $11.5 Million in Funding to Advance AI-Powered Remote Video Guarding Solutions"↗
- 19PR Newswire — "Aegis AI Announces Rebrand to Actuate" (2019)↗
- 20Intel Capital — "Deep Sentinel Secures $15 Million in Series B Funding to Accelerate AI-Powered Security Growth"↗
- 21SDM Magazine — "Graham Partners Acquires Immix to Accelerate the Future of RVM and Managed Security Services"↗
- 22Security Info Watch — "Immix Software Sold to Private Equity Firm" (Norland Capital, 2021)↗
- 23SDM Magazine — "Bold Technologies and Perennial Software Merge"↗
- 24BusinessWire — "Alarm.com Showcases Unified Platform Growth and AI-Powered Innovation at ISC West 2026"↗
- 25BusinessWire — "Eagle Eye Remote Video Monitoring Delivers Affordable, Professional, Real-Time Crime Prevention"↗

