AI Agent Development Services We Offer in Portland
Portland agent work divides cleanly into three security postures, and we build all three. Fab and equipment buyers get fully self-hosted agents: open-weight models on private GPU capacity inside the plant network, retrieval limited to internal document stores, read-only connectors into MES, SPC and tool-log systems, and a mandatory human gate on any write to a recipe or a lot disposition. No prompt, no context window and no trace ever leaves the site. Health systems get agents inside a HIPAA perimeter under a signed BAA, with clinician override on every clinical-adjacent output and citations back to chart documentation so a reviewer can verify rather than trust. Consumer brands and utilities get customer-facing agents, which is where Oregon law bites hardest: any agent that holds a sustained, personalized conversation needs to be assessed against SB 1546's AI companion definition, any agent touching location needs an HB 2008 review, and any agent presenting itself in a care role needs an HB 2748 title check. Every engagement ships a tool allow-list with per-tool policy gates, an action log keyed to user, tool, policy decision and outcome, a NIST AI RMF-aligned risk profile, a documented kill switch, and an OCPA data-protection assessment covering the agent's retention and deletion behavior.
Our AI Agent Development Development Process
Discovery starts with three Oregon-specific screens rather than a generic risk workshop. First, an OCPA scoping pass: does the buyer clear the 100,000-consumer or 25,000-plus-25-percent-of-revenue threshold, what sensitive categories will the agent touch, and can the buyer answer the OCPA request for a list of the specific third parties that received a given consumer's data once model providers, vector stores and observability vendors are in the pipeline. Second, an HB 2008 pass on precise geolocation and on any consumer the buyer knows or willfully disregards is under 16. Third, an AI-specific pass covering SB 1546 companion characteristics, HB 2748 title restrictions, and whether the deployment is consumer-facing enough to attract Attorney General attention now that the mandatory 30-day cure period sunset on January 1 2026. Design produces a tool allow-list with four gate tiers and a written policy per tool. Build sprints run two weeks with Thursday demos at 2:00 PM Pacific, continuous red-teaming through PyRIT and Garak plus a Portland scenario pack covering prompt injection, IP exfiltration and PHI leakage. Deployment ships immutable action logs into the SIEM your security team already runs, a tested kill switch, and a documentation pack an Oregon DOJ inquiry can be answered from.
Process Discovery
1-2 WeeksWe sit with the people doing the work in {city} and record the real process — including the exceptions they handle by instinct, which are exactly what kill naive automations.
Tool Surface Design
1-2 WeeksEvery system the agent touches gets a typed, permission-scoped tool with its own rate limit and rollback path. The agent gets a narrow set of verbs, never raw admin access.
Build & Evaluate
3-6 WeeksThe agent is built alongside its evaluation suite from day one, using real tasks from your business with verified outcomes. Every change is scored before it ships.
Shadow Mode
2-3 WeeksThe agent runs against live traffic but commits nothing. We compare its proposed actions to what your team actually did and tune until agreement is high enough to trust.
Staged Autonomy & Run
OngoingAutonomy is released by risk band — reversible actions first, irreversible ones keeping a permanent human gate. Then we monitor completion rate, escalations, latency and spend.
Technologies We Use for AI Agent Development
Portland has the best cloud adjacency of any US metro for agent workloads, and we use it. AWS us-west-2 is physically in Oregon, in the Columbia Basin east of Portland, so Bedrock inference, EKS orchestration and OpenSearch retrieval all sit in-state with single-digit to low-teens millisecond round trips from a downtown office. Google Cloud us-west1 is in The Dalles, about 80 miles up the Columbia River, which makes Vertex AI with Gemini a genuine in-state option. Azure has no Oregon region; buyers standardized on Azure OpenAI run in West US 2 in Washington State, which is still in-region for Pacific Northwest latency but is a different state for residency arguments, and we say that out loud during architecture review rather than after. Orchestration is LangGraph where the workflow is a state machine we need to reason about, CrewAI where role specialization matters, Microsoft AutoGen for Microsoft 365 shops, and the OpenAI Assistants API where a vendor-managed runtime is acceptable. Tools connect over Model Context Protocol servers when the buyer accepts the standard and typed REST clients otherwise. Tracing runs on LangSmith, LangFuse or Arize Phoenix. Guardrails sit on NeMo Guardrails, Lakera Guard and Llama Guard. Air-gapped fab work runs Llama, Mistral or Qwen weights on on-premise GPUs with pgvector or Qdrant for retrieval and zero outbound calls.
Other Services We Offer in Portland
Looking for a different service? Explore our full range of technology solutions available in Portland.
Explore Our AI Agent Development Specializations
Dive deeper into our specialized ai agent development offerings.
AI Agent Development in Other Cities
We deliver ai agent development solutions across 45 cities in 24 countries. Find a location near you.
Latest Work
Drag to explore or use arrow keys


