Across every major industry—from financial services to healthcare to government—regulators are watching. And they’re not impressed.
As enterprises embrace hybrid work, mobile-first cultures, and increasingly AI-powered collaboration tools, they’re also creating dangerous gaps in their compliance posture.
Data retention, call recording, and policy enforcement are under the spotlight as regulators intensify scrutiny. And many organizations, especially those relying on patchwork solutions or personal devices, are quietly falling behind.
“Companies often overlook the extent or the options that their employees have to communicate—and those modes that require compliance and security controls,” says Doug Jones, AVP of Product Management, Voice & Collaboration at AT&T. “You need to think about this end to end—across any device, any app, any mode of communication.”
The Evolving Compliance Landscape: More Devices, More Risk
Five years ago, enterprise compliance strategies largely focused on email and traditional phone systems.
Now, regulators expect organizations to demonstrate control across a vast landscape of communication channels:
- Microsoft Teams and many more
- Contact center platforms (CCaaS)
- Mobile-native apps
- Personal devices used in remote or hybrid work settings
- AI-generated meeting summaries and screen captures
For highly regulated sectors such as finance and healthcare, the bar is rising fast.
“Remote work has enabled flexibility - but also created a nightmare for companies trying to ensure compliance across all these modes of communication,” says Jones.
“Now you’ve got half a dozen different ways an employee might interact with clients or partners. They all need to be secure—and compliant.”
The Hidden Risks of Personal Devices
Many organizations embraced BYOD strategies early in the hybrid work era, hoping to balance flexibility with cost savings. But today, personal device usage creates significant blind spots—especially in high-stakes environments like trading floors or healthcare contact centers.
While BYOD can be an enabler, Jones warns that oversight and policy enforcement must be fully integrated—not an afterthought.
“Just because a UC app is installed on a device doesn’t mean it’s the only way users will communicate,” he explains. “Without tight integration, employees can bypass apps and use native calling—and that’s where compliance risk creeps in.”
AT&T and Microsoft Teams Phone: Securing Communications End-to-End
To help enterprises meet this challenge, AT&T has developed deep integrations with leading UC platforms—including Microsoft Teams Phone.




