NASCIO Contacts: Doug Robinson, Executive Director and Meredith Ward, Deputy Executive Director
The 2026 NASCIO State CIO Survey, The State CIO in Motion: Priorities, Pressures and Progress, captures insights from 51 state and territory chief information officers on the issues shaping state technology leadership. The survey explores how CIOs are navigating growing demands around digital services, technology investment governance, critical infrastructure cybersecurity, data center strategy, artificial intelligence, IT accessibility and acquisition. Findings point to a state CIO role that is increasingly focused on enterprise leadership, cross-government collaboration and measurable public value, while also confronting workforce pressures, funding constraints, rapidly evolving technologies and rising expectations for secure, accessible and modern government services.

Table of Contents
- Executive Summary
- CIO Organization Advice from the Trenches
- Digital Services Transformation
- Technology Investment Governance and Management
- Critical Infrastructure Cybersecurity Protection
- Data Center Strategy
- Artificial Intelligence and Emerging Technology
- IT Accessibility
- Acquisition
- List of Participating States and Territories
Executive Summary
You have now arrived at the 2026 State CIO Survey, our 17th edition. Fifty-one state and territory chief information officers (CIOs) answered approximately 40 questions on eight topics in the summer of 2026. This year’s survey also includes responses collected from many open-ended questions and state CIOs were, as usual, generous with their time and thoughts. Next year could bring significant change in the state CIO world as there are 36 gubernatorial elections. CIOs gave us their best advice for the likely new crop of CIOs coming in 2027 as a result of those elections. We asked CIOs about some evergreen topics like artificial intelligence (AI) (yes AI has become evergreen), digital government services and technology investment management. We also asked some new questions about critical infrastructure cyber protection and data centers—do state CIOs have a role to play in the current public debate about data centers? Read the report to find out!
CIO Organization Advice from the Trenches
As happens every four years or so, in November 2026 there will be many gubernatorial elections—36 to be exact. This will likely bring many new state CIOs in 2027, which means we thought now is the best time to ask current state CIOs for their words of wisdom. We first asked what the strategic business role of the state CIO is. The responses we received can be summed up by saying that the state CIO has evolved into an enterprise business leader, not only a technology operator.
State CIOs told us that operational excellence remains the foundation for transformation. One CIO advised new CIOs to, “Ensure that the state technologies run smoothly since you cannot innovate in the middle of operational chaos.” Additionally, CIOs told us that the role requires balancing immediate demands with long-term modernization within the lightning speed pace that technology is evolving. “The CIO is a chief problem solver, as technology is ingrained into every level of business,” another CIO told us.
Not surprisingly, when describing the role of the state CIO, the advice was also heavy on the importance of interpersonal skills (we used to call this “soft” skills). The CIO must bridge fragmented government silos and build cross-boundary relationships. One CIO told us, “[The CIO is a] communicator, connector and must ultimately find ways to remove any pain related to getting business done and visions reached. Certainly, securely and transparently.” Unsurprisingly, CIOs talked about the necessity of relationship building and communication (both with others and communicating value) as central keys to success. As technology is a part of almost every facet of government these days, CIOs told us that it is crucial that, “A new CIO must sit at the leadership table, not in the basement.”
State CIOs are now operating in a more uncertain environment with the devolution of federal program administration, cost shifts and instability. With these changes, demands on the states are increasing and citizen expectations are as well. AI has certainly added pressure as a prominent disruptor to the status quo. We asked CIOs if they anticipate increased turbulence and disruption in the state CIO role and organization over the next five years and 68 percent said yes, 22 percent maybe and 10 percent no.

Of course, we couldn’t resist asking CIOs to elaborate and they told us that higher public expectations, artificial intelligence, the growth and increasing sophistication of cyber threats, aging legacy systems and emerging technologies will continue to create operational and strategic risk. One state CIO framed it like this: “The state CIO is being asked to move faster while also improving security, accessibility, resilience, fiscal discipline and transparency.” Indeed, CIOs will be asked to move faster while managing greater constraints, thus making it harder for CIOs to deliver services at the pace expected. One CIO said, “We are reaching a point where traditional approaches (planning, budgeting) need much shorter cycles than our processes allow. I don’t see any set of circumstances where the state CIO job gets easier.”
One disruptor that CIOs told us they are increasingly facing is that technology decisions are becoming more political and public facing. Issues such as AI use, surveillance concerns, data center energy and water demands, accessibility, transparency and resident expectations are pushing CIO decisions into broader policy and public trust conversations. While AI is seen as a dominant disruptive force, it is also an opportunity and a source of pressure, reshaping service delivery, workforce needs, governance, risk management and the definition of technology work itself.
One CIO described the state CIO office as being on a “workforce cliff,” as retirements, loss of institutional knowledge and changing skill requirements are expected to challenge CIO organizations as they try to modernize and maintain critical services. The same CIO continued, “The people who hold the institutional knowledge of our legacy systems are retiring, the pipeline behind them is thin and AI is simultaneously redefining what an IT job even is.”
We had a hunch that CIOs would want to talk about their technology workforce, so we asked how they are cultivating the future CIO organization workforce. While state CIOs are turning to a whole host of strategies and upskilling, investing in training and establishing talent pipelines were the most chosen.
We also gave CIOs a hypothetical magic wand and asked what one thing they would change about the CIO position in their state. Many CIOs continued their calls for a move away from the inflexible chargeback model. Respondents repeatedly pointed to the need for more sustainable enterprise funding models in order to create dedicated funding for innovation, cybersecurity and transformation. CIOs also stressed the importance of cybersecurity and continue to value a whole-of-state cybersecurity model. CIOs told us that the existing procurement laws and processes remain a barrier to speed and modernization. Reducing procurement timelines and friction was identified as a key change that would help CIOs deliver more quickly and effectively.
Source: The 2026 NASCIO State CIO Survey
Even though we gave state CIOs a make-believe magic wand, in the real world, the role continues to be constrained by capacity and time. When asked what one thing they would change, one CIO said they wished for “More hours in the day—so many opportunities to improve things.”
We also had a hunch that responses to this section would include the good, the bad and the uncertain, so we wanted to end on a high note. We asked current state CIOs to give their best advice on the role for the next wave of state CIOs. They stressed the need to be a business leader and public servant. One told us, “Most importantly, remember that the purpose of technology in state government is not technology itself. The purpose is better service, better decisions, better stewardship and stronger public trust.” Another said, “Be humble. Be vulnerable. Be human.”
CIOs talked about the importance of building relationships and coalitions before driving change to create lasting impact:
“Listen and learn first. The system that you are joining has been here long before you and will be here long after.”
“Build partnerships! Authoritarian leadership style imposes unneeded roadblocks to progress.”
“The hardest problems are never technical.”
CIOs made it clear that there are certain things that can’t be compromised: “Make the technology organization easier to work with, but also make clear that enterprise standards, security, accessibility, architecture and fiscal discipline are not optional.” However, perfection isn’t attainable: “There is no ‘done.’ There is only ‘better.’ Celebrate when you get better.”
CIOs talked about the importance of leading now: “Always lead with value creation and capture. Don’t have a grand plan that creates value five years from now (you likely won’t be around!). Have a long-range plan but generate and capture value at least every six months.” In the same spirit of planning for the future, another CIO told us to, “Always be in the business of succession planning. We need leaders willing to take risks, bring in the best talent and let each individual contribute at their maximum rate and then move on to make room for the next wave. Like shark’s teeth.”
To close out this section, we will add a bit of advice for new CIOs from NASCIO: remember you are not alone. The NASCIO community is made up of current and former state technology folks who are always willing to listen, help and support.
Digital Services Transformation
Ensuring that citizens have access to digital services has been a key component of nearly all state efforts to modernize and improve their IT service offerings. States have invested in secure online portals, mobile applications, digital identity solutions and have modernized the systems that allow citizens to access services anytime and from anywhere. Doing so, however, requires a holistic mindset. As one CIO put it, “States need to think beyond individual applications and toward common capabilities such as identity, payment, notification, data exchange, accessibility, cybersecurity and cloud-enabled platforms. The real opportunity is to create digital services that are secure, accessible, measurable and easier for citizens to use across agency boundaries.”
Despite the enthusiasm for digital transformation, states may be limited by a number of factors in expanding their offerings. As with many areas of IT investment, securing adequate funding to assist in digital transformation has been difficult. States are about evenly split on having dedicated funding for advancing citizen digital services (55 percent do; 45 percent do not). Of those who responded “yes,” they listed several factors that continue to constrict funding for digital services, including:
- Long-term state budget uncertainty
- Funding for digital transformation being fragmented across many agencies
- Technology emergencies that require immediate resources
- Being able to pay for improvements only from one-time funding sources
- Demand growing faster than offerings can reasonably be expanded
- Management of and complexities with vendor relationships
When asked how the CIO organization is approaching business relationship management (BRM) to assist with the modernization of digital service delivery, survey participants cited focusing on customer relationship management as the top response (86 percent). Additionally, CIOs highlighted other approaches.
Overall, the shift toward digital services has altered how many CIO offices approach BRM. In a number of instances, CIOs were drastically rethinking their BRM functions or standing up entirely new ones that had not previously existed. A common theme of the new and improved BRM functions was to instill an ability to both tailor needs to each agency and to respond rapidly to new requests.

We also asked CIOs about major challenges in meeting the demand for citizen digital services. While CIOs identified it as the top obstacle, funding alone is not the only hindrance to modernizing digital services. One CIO stated that while funding was an issue, “skills, abilities, capacity and trust all loom larger than funding.”
Major Challenges in Meeting Demand for Citizen Digital Services
respondents selected top 3
Lack of adequate funding and budget to balance immediate public needs with future critical investment (66%)
Lack of trust in shared digital solution provisioning, coordination and effective support for digital solution offerings (32%)
Workforce skills and capability constraints to deliver and implement digital services (28%)
| Lack of organizational agility/flexibility | 26% |
| No dedicated digital services team | 26% |
| Data and information quality constraints | 26% |
| Inability to envision and operationalize new ways of providing government services | 22% |
| Citizen expectations exceed organizational capabilities | 16% |
| Lack of internal willingness to take risks or embrace innovation | 16% |
| Lack of strategy and vision to implement | 12% |
| Regulatory policies and procedures present roadblocks to innovation | 8% |
Source: The 2026 NASCIO State CIO Survey
Respondents also cited procurement rules, AI-related security challenges and increased cybersecurity attacks, time constraints, problems in pivoting to new missions and difficulty in understanding what the public actually wants from digital government. One CIO also identified the structure of government itself as a key obstacle in moving more services online:
“Government is organized in verticals, with each agency owning its programs, systems and budgets, while citizens experience government as a single horizontal journey that crosses those boundaries. Without a common citizen identity, residents re-establish who they are at every door, and the state cannot easily recognize a person it has already served. Compounding this, legacy procurement and budgeting cycles are built for one-time capital projects rather than the iterative, continuous-delivery model that modern digital services require. Closing the gap is less about new technology than about aligning funding, acquisition and organizational structure around the citizen’s journey rather than the agency’s org chart.”
Finally in this section, we asked respondents how the requirement to use the .gov domain is established across state executive branch agencies. Sixty-six (66) percent of CIOs said it is required by CIO directive or policy, while 38 percent said it is governed by the state’s enterprise architecture.
Policies around .gov adoption vary widely among states, but there is a broad consensus that .gov adoption is critical for cybersecurity protection, ensuring public trust and establishing clear authority. NASCIO consistently advocates for greater adoption of the .gov domain because it increases both cybersecurity and digital trust.

Technology Investment Governance and Management
As technology spending continues to grow across state government, CIOs are under increasing pressure to ensure that investments support statewide priorities, deliver measurable value and responsibly steward public resources. Effective IT investment governance provides the structure for evaluating competing priorities, balancing enterprise and agency needs and directing limited resources toward initiatives that advance strategic outcomes. Understanding how states organize these governance practices offers insight into the evolving role of the state CIO in enterprise decision-making.
Most states are employing more than one approach to IT investment governance. This demonstrates the complexity inherent in IT investment governance and the level of effort state CIOs are putting forth to ensure effective investment in information technology. Rather than relying on a single approval authority or governance mechanism, CIO organizations are combining strategic alignment, governance boards, formal policies, staged investment reviews and collaborative budget oversight into integrated governance models. The four most common approaches employed are:
- Alignment between IT spending decisions and statewide priorities, outcomes and mandates
- Enterprise governance review and approval board, committee or council
- Formal IT investment governance directives or policies
- A stage-gate oversight process for investment approvals
State Approaches to IT Investment Governance
respondents selected top 3
Alignment between IT spending decisions and statewide priorities, outcomes and mandates (61%)
Enterprise governance review and approval board, committee or council (53%)
Formal IT investment governance directives or policies (53%)
| A stage-gate oversight process for investment approvals | 47% |
| Shared approval authority with the state budget office (joint sign-off) | 39% |
| Dedicated governance or specialized funding for legacy modernization | 35% |
| Direct CIO office approval agency of IT budget request | 29% |
| Use metrics and key performance indicators to assess IT value | 29% |
| CIO office only advises the state budget office on agency IT requests | 28% |
| Using a recognized framework to guide investments | 26% |
| CIO office has no formal role in agency IT budget requests | 12% |
Source: The 2026 NASCIO State CIO Survey
Next in this section, we asked about frameworks and disciplines used by the CIO organization to guide and measure the cost of technology. State CIOs increasingly rely on established voluntary frameworks such as NIST, reflecting the continued importance of cybersecurity and risk management in technology planning. They also rely on enterprise portfolio management, underscoring the growing emphasis on enterprise planning, investment governance and aligning technology decisions with statewide priorities. Together, these approaches can improve investment decisions, strengthen governance and provide a better understanding of the cost and value of technology. These frameworks provide common terminology, structured processes and repeatable practices for evaluating investments, managing enterprise portfolios and aligning technology with business priorities.
Frameworks and Disciplines Used by the CIO organization to Guide and Measure the Cost of Technology
respondents allowed to make multiple selections
NIST frameworks (57%)
Enterprise Portfolio Management (EPM) (51%)
Enterprise and business architecture (47%)
| IT investment management | 45% |
| ITIL (Information Technology Infrastructure Library) | 41% |
| Activity-based costing/management | 39% |
| FinOps | 37% |
| Technology Business Management (TBM) | 28% |
| COBIT (Control Objectives for Information Technology) | 8% |
| ISO/IEC 38500 (the international standard for IT governance) | 8% |
| None | 8% |
Source: The 2026 NASCIO State CIO Survey
As technology environments become more complex, the use of multiple complementary disciplines and frameworks enables CIO organizations to balance operational excellence, financial stewardship and strategic planning. The findings also suggest that states are blending strategic, operational and financial disciplines to support enterprise decision-making. Rather than competing approaches, these frameworks appear to serve complementary roles across the technology management life cycle.
To close out this section, we asked a few open-ended questions starting with how rates are established in a chargeback model. As enterprise technology services continue to expand, CIO organizations are increasingly expected to recover costs in ways that are transparent, equitable and sustainable. Chargeback and fee-for-service models have been around for decades and help fund shared technology services, but they also require governance processes that balance financial stewardship with customer expectations. The responses also demonstrate that establishing service rates has become an enterprise governance process rather than solely a financial exercise.
Several patterns emerged from the responses:
- Most states review rates annually, while others align reviews with biennial budget cycles or conduct periodic variance analyses
- Rate review committees, governance boards, budget offices and legislative approval frequently play a role in the rate-setting approval process
- Most states invite agency participation through governance committees, formal review processes or ongoing collaboration, although the level of participation varies
- Several states described moving toward hybrid funding models that combine enterprise appropriations with traditional chargeback mechanisms
Finally, several responses suggest that states are beginning to rethink traditional chargeback models. Rather than relying exclusively on direct cost recovery, some respondents described hybrid approaches that combine enterprise-funded shared services with direct billing for specialized services. These approaches seek to improve cost predictability, reduce administrative complexity and better support enterprise capabilities such as cybersecurity, digital platforms and modernization initiatives.
The final question in this section was about measuring the value of technology. As technology spending becomes an increasingly significant component of state government operations, CIO organizations face growing expectations to demonstrate the value of technology investments. While controlling costs remains important, state leaders are also seeking evidence that technology improves government services, reduces risk, supports agency missions and delivers meaningful outcomes for residents.
Responses present some patterns suggesting that state CIOs are:
- Demonstrating business outcomes by measuring service delivery, operational efficiency, citizen experience, workforce productivity and mission outcomes
- Evaluating risk and resilience via cybersecurity posture, risk reduction, resilience and modernization progress
- Ensuring strategic alignment by connecting technology investments to statewide priorities, enterprise strategies and modernization roadmaps
- Measuring performance based on budgets, ROI, project delivery, utilization and consumption metrics
- Continuously improving by actively developing formal value measurement methodologies and enterprise metrics
The responses also suggest that states are moving toward more comprehensive approaches to value realization. Several respondents noted the importance of reduced complexity, enterprise reuse, cloud optimization and modernization outcomes alongside traditional financial measures. As enterprise technology becomes increasingly integrated into government services, CIO organizations are seeking more meaningful ways to demonstrate how technology investments contribute to long-term public value rather than simply documenting project completion or budget performance. We anticipate more innovative approaches for measuring value will arrive as we move into the future.
Critical Infrastructure Cybersecurity Protection
It is no surprise that 88 percent of surveyed state CIOs identified the threat level of critical infrastructure cybersecurity attacks as an area of high concern. These include communications networks, electric grids, water/wastewater systems, data centers, hospitals and oil pipelines. The remaining respondents categorized the threat as a medium concern. CIOs identified numerous reasons for their concern. One stated that “in rural states the exposure is concentrated in under-resourced operational systems — small water and wastewater utilities, rural health care and the energy grid. The threat is high and the defenders are thin.”

CIOs stated that frontier AI models, a lack of resources, geopolitical tensions and the fact that many systems were outside of their direct control as being significant causes for concern. As one respondent noted, “If your concerns are not significant, you need to pay more attention.”
We next asked if critical infrastructure cyber protection (CICP) is part of the CIO’s whole-of-state plans and an overwhelming majority (73 percent) said yes. Of those who answered “no” to this question, many indicated that they were working toward this goal or that the responsibility to critical infrastructure incidents falls outside of their office.
Several CIOs also provide CICP services to other entities within the state, with the top two responses being other branches of government and local entities. When elaborating on what services were provided, CIOs highlighted training, awareness, scanning, assessments and other basic services.

CICP Services Offered Beyond Executive Branch
respondents allowed to make multiple selections
| Yes, other branches | 57% |
| Yes, local governments, public libraries and special districts | 55% |
| Yes, K-12 school districts | 53% |
| Yes, higher education | 35% |
| Yes, tribal governments | 28% |
| Yes, public hospitals and health care facilities | 24% |
| No | 24% |
| Yes, public electric, water and wastewater utilities | 22% |
Source: The 2026 NASCIO State CIO Survey
When asked about funding for CICP, about half (49 percent) have funding to support local entities. To help fill these gaps, CIOs credited partnerships with MS-ISAC, fusion centers, emergency management operations and a reliance on the State and Local Cybersecurity Grant Program (SLCGP) as critical in delivering these services. The SLCGP was identified by a number of respondents as vital to funding local entities for CICP. According to one CIO, “SLCGP funding is used to strengthen cybersecurity capabilities, improve resilience, address identified risks, enhance incident response preparedness and implement cybersecurity best practices.” Many CIOs expect that the explosion of AI will create a much greater demand and need for this type of funding.
For an in-depth look into critical infrastructure cyber protection, see NASCIO and GDIT’s publication on this topic.
Data Center Strategy
With expanded AI usage across the country, data centers have become a hot topic of discussion for the public, in the media and in legislatures. However, for state CIOs, data centers and their operation, optimization and consolidation have been an area of priority for decades. We wanted to know what state plans for data center activity are in the next two to three years.
State Plans for Data Centers in Next 2-3 Years
respondents allowed to make multiple selections
Expand use of public cloud infrastructure (73%)
Adopt a hybrid model (combination of state-owned and cloud/third-party) (55%)
Maintain current state-owned data center footprint (49%)
| Downsize or right-size the state’s primary data center | 43% |
| Expand cloud use specifically for disaster recovery or business continuity | 41% |
| Consolidate agency-owned data centers under centralized CIO authority | 26% |
| Reduce the total number of agency-owned data centers | 26% |
| Migrate to a co-location facility (state equipment in a third-party facility) | 18% |
| Outsource data center operations to a 3rd-party MSP (on-premise) | 10% |
| Expand state-owned and operated data centers | 6% |
| Consolidate or reduce the number of third-party data center vendors | 6% |
| Expand use of third-party hosted data centers | 4% |
| Exit the state-owned data center model entirely (full third-party reliance) | 4% |
Source: The 2026 NASCIO State CIO Survey
The top five responses suggest states are making moves:
Expand use of public cloud infrastructure (73 percent). This is the highest priority for state CIOs—they want to move more infrastructure, applications, storage, backups and other workloads to public cloud infrastructure (meaning a third party, off-premise provider). One CIO stated, “This represents the best value for dollars due to its elasticity and scalability as well as ready access to emerging technologies in secured environments.”
Adopt a hybrid model (combination of state-owned and cloud/third-party) (55 percent). A significant number of state CIOs describe a hybrid model that combines public cloud with selected state-operated, hosted or collocated infrastructure. “A hybrid cloud strategy improves resiliency, reduces unnecessary duplication, supports agency modernization and positions the state for future digital services and AI-enabled capabilities,” according to one CIO who is prioritizing this approach.
Maintain current state-owned data center footprint (no significant change) (49 percent). Some states plan to keep a meaningful physical data center footprint and invest in modernizing core infrastructure, improving reliability, reorganizing facilities or maintaining service quality. One CIO made the argument for this choice by saying “We are able to deliver the flexibility and extensibility of cloud at a lower cost point in most cases once the total cost of ownership in the cloud is calculated.”
Downsize or right-size the state’s primary data center (43 percent). Many states also want to reduce the primary data center as well as the number of agency-owned/operated data centers, eliminate duplicative infrastructure, right-size local capacity or close legacy facilities. “Our top priority is vacating a legacy on-premise data center and migrating to a hosted and managed service solution,” one CIO said.
Expand cloud use specifically for disaster recovery or business continuity (41 percent). Cloud-based disaster recovery, disaster recovery as-a-service, stronger business continuity and improved operational resilience appear repeatedly in CIO comments. According to one state CIO, “Implementing a cloud disaster recovery strategy is our top priority to drive toward a hybrid model.”
When state CIOs were asked to estimate how much of their state’s current compute environment is on-premise in state-owned data centers, the numbers varied widely. Responses reflected that on-premise compute remains a substantial part of most state IT environments. Answers ranged from zero to 90 percent, with a median of 60 percent.
Given recent debates stemming from public backlash against the energy use, water demands and other environmental impacts of expanding data centers to facilitate emerging AI advances, we wanted to know what role, if any, state CIOs have in this debate. Slightly more than half of CIOs described a current or expected role, including task force participation, advising governors or legislative leaders, providing technical expertise or answering questions when requested. As one CIO told us, “The CIO role is to provide balanced, practical guidance that considers economic opportunity, environmental stewardship, infrastructure readiness, cybersecurity and the long-term technology needs of the state.”
Among CIOs who asserted they did not have a role in this debate, common explanations included that the issue is handled by economic development, environmental agencies, utilities, local government or governor’s office policy teams. A few also noted that the issue had become politically contentious and expressed reluctance to enter the debate. One state CIO commented, “This is going to be a huge deal for some state CIOs and society as a whole. Resiliency will be required!”
Artificial Intelligence and Emerging Technology
It’s been three and a half years since generative artificial intelligence (GenAI) was made widely available. For the first time this year, artificial intelligence (AI) made it to the number one spot on the NASCIO State CIO Top 10 Priorities list for 2026. States are finding that AI has been integrated into familiar platforms, employees are expected to use it, AI projects have expanded from pilots to scaled initiatives and we know from our own internal data that about half of states have hired someone with “AI” in their job title. The conversation has also shifted from what can AI produce (generative AI) to what can AI do (agentic AI). AI is changing how states do business and changing it at a rapid pace.
As we have in the last two years, we asked state CIOs which action items regarding generative AI (GenAI) have been implemented in their states. The biggest shift is that almost all states have implemented enterprise policies and procedures on development and use of AI (98 percent, up from 76 percent in 2025). Two other big shifts were the number of states that have put in place procurement terms and contract provisions around GenAI (61 percent, up from 41 percent in 2025) as well as the number who have addressed transparency and accountability (61 percent, up from 41 percent in 2025). The number of states that have implemented responsible use, flexible guardrails, security and ethics stayed level (88 percent) as did the number of states that have created advisory committees and task forces (82 percent).
What States Have Implemented for GenAI
respondents allowed to make multiple selections
98%
Enterprise policies and procedures on development and use
88%
Responsible use, flexible guardrails, security, ethics
82%
Creation of advisory committees and task forces
| Adopted a governance framework | 79% |
| Inventory and documenting uses in agencies and applications | 77% |
| Procurement terms and contract provisions | 61% |
| Transparency and accountability | 61% |
| Data governance: data sources, data quality, bias, data privacy | 57% |
| Requiring disclosure by software providers | 49% |
| Impact on operations and workforce | 37% |
Source: The 2026 NASCIO State CIO Survey
While these numbers have improved, there is still work to be done. As one state CIO said, “Virtually all options were selected with the caveat that these efforts are very early, immature and/or not strictly enforced. We still lack broad understanding and socialization of our AI policy, making enforcement and governance difficult.”
AI governance, a critical component, has been improving as well. This year, 78 percent of state CIOs reported that they had adopted an AI governance framework (up from 65 percent in 2025). We asked state CIOs this year about the drivers of central AI governance in their state. The most popular answers were the needs of the business/customer (82 percent), the state enterprise architecture (73 percent) and the state cybersecurity roadmap (71 percent). “We went through a phase of chasing AI ‘quick wins’ in mid-2025, with modest success. The exercise taught most participants and stakeholders that meaningful efficiencies from AI require more planning and broader application,” said one state CIO.

Given the risks of using AI in state government, this year we asked state CIOs an open-ended question about whether their organization has included safety and ethics guardrails in its AI governance, guidance and operations, and if so, how. About two-thirds of state CIOs said that they were actively incorporating safety guardrails. The most common answer was that they had put AI safety guardrails into enterprise or statewide policies. Many states also said that they are required to review AI before deploying or purchasing it and that AI safety is aligned with privacy, data protection and cybersecurity governance. “The CIO organization has an important role in helping agencies understand where AI can add value, where it introduces risk and how to move from pilots to responsible operational use,” explained one state CIO.
Again, this year we asked CIOs what GenAI activities they have in place. Ninety-four (94) percent have pilot projects and 92 percent have proofs of concept—both have slightly higher numbers than last year. Although we did not ask about projects in production last year, this year 82 percent of states reported having projects at that stage. We also asked for the first time about enterprise-scale projects across the executive branch, with 35 percent of states reporting instances of this progress. These two new metrics indicate that states have moved beyond pilots into scaled production of AI.

Unfortunately, dedicated funding remains a challenge as only 28 percent of CIOs report dedicated funding for AI initiatives. This is just slightly higher than the 25 percent reported in 2025. Given the high prevalence of AI in states, funding must be coming from other nondedicated sources and/or be more limited than states would like. “We still do not have dedicated funding for AI which makes it difficult to move quickly with additional pilot projects, proofs of concepts, and expanding the sandbox,” explained a state CIO.
An important conversation among state technology leaders has been about how to measure return on investment (ROI) when it comes to AI, so we asked CIOs how they evaluate or measure the success of AI activities. Overall, the responses suggest that states are moving through a progression in how they evaluate GenAI initiatives. Early efforts tend to focus on participation—tool usage, training, employee adoption and the number of pilots launched. As programs mature, states begin measuring project-level results, including estimated time saved, workload reduction, user feedback and improvements in accuracy or service delivery. The most advanced approaches connect these results to broader business outcomes, ROI, resident value and the ability to scale across government. Across all stages, states increasingly view security, privacy, governance and responsible use as essential parts of success as well. One state CIO summed it up by saying, “The priority is not simply to experiment with AI, but to learn which use cases can be implemented responsibly and scaled where they create measurable value.”
This is the third year we have asked if employees in the CIO’s organization are using generative AI tools in their daily work and this year 96 percent said they are! This is a big jump from just 54 percent two years ago. While not every employee in every state is using it, at least some employees have been given licenses to use GenAI at work in almost every state CIO organization.
To learn more about the GenAI work in states, we asked about the estimated number of GenAI projects in production across the executive branch. The numbers varied widely, from “four” to “thousands.” Some CIOs had difficulty even estimating the number, saying things such as, “It’s hard to say since it’s embedded in so many activities.”
For the first time this year, we asked the CIO if their state is using agentic AI in any state operation. Twenty-nine (29) percent said yes, 35 percent said use of agentic AI is planned and 29 percent said no (others were unsure).


The most common application of agentic AI is in workflow and process automation. Other popular answers were IT operations, application development, coding, modernization and customer service/contact centers. The dominant application area is for automating repetitive internal work, including routing, approvals, reviews, back-office tasks, data processing, procurement and IT governance. As with GenAI, states are taking thoughtful, internal approaches with agentic AI first. “We will prove it internally, with a human accountable for every consequential action, before extending it to citizen-facing operations,” explained one state CIO.
State CIOs clearly see a lot of potential in agentic AI. Sixty-four (64) percent said that agentic AI will be the most impactful emerging technology in the next two to three years, followed by GenAI with only 14 percent. One CIO stated, “I think the agentic AI revolution has the potential to dramatically transform government. We have spent decades building software systems with a user interface that assumes the user is a human. What happens when that is an AI agent? The process of business fundamentally needs to change.”

Ten percent of state CIOs said that quantum computing would be most impactful, but most CIOs see it as a future development. When we asked about the status of quantum computing in their state governments, 73 percent of state CIOs said they are monitoring developments and have taken no formal action on it yet. As one state CIO put it, “We have generally been discussing quantum but there is limited impact expected so AI is prioritized.”
Status of Quantum Computing in States
respondents allowed to make multiple selections
73%
Monitoring developments (no formal action yet)
26%
Partnering with universities or research institutions
18%
Policy discussions are underway
| Engaging with federal agencies or interstate peers | 14% |
| Post-quantum cryptography/quantum-safe security initiative underway | 14% |
| Planned but not yet started | 12% |
| Advisory team or working group formed | 10% |
| No current plans | 8% |
| Budget or funding allocated for quantum-related activities | 6% |
| Quantum readiness assessment completed on operations and workforce | 4% |
| Enterprise policy or strategy established | 2% |
| Proof of concept or sandbox environment established | 2% |
| State employee awareness or training programs are underway | 2% |
Source: The 2026 NASCIO State CIO Survey
So, what’s next? State CIOs mentioned the following themes for what they expect to focus on related to emerging technology over the next few years:
- Moving from pilots and experimentation to scaled, operational use
- Improving governance, policies, standards and responsible-use guardrails
- Addressing cybersecurity and AI-specific security risks and opportunities
- Exploring agentic AI as a major next phase
- Improving data readiness, governance, privacy or sovereignty
The recurring message is that states will need to strengthen governance, cybersecurity, data, procurement, workforce readiness and cost controls at the same time they expand adoption of AI.
IT Accessibility
IT accessibility (sometimes abbreviated as A11y) moved from up to number six from number 10 on the 2026 State CIO Top 10, signaling national growth and understanding of digital accessibility as a core enterprise principle. The inaugural NASCIO State Accessibility Officer Survey found that 40 out of 56 (more than 70 percent) of states and territories have a state digital accessibility lead. However, there are many differences in job titles across organizational structures and reporting models. The CIO’s most critical enterprise digital accessibility leader is the chief digital accessibility officer (CAO). In this year’s state CIO survey, we found that 44 percent of states have a CAO, including four percent that report outside the CIO organization. Conversely, 46 percent of states do not have a CAO while six percent are in process of recruiting.

Some CIOs indicated roles like “DEI director” absorb all duties of a standard CAO without the title. These findings highlight the need for broader establishment of the CAO within state IT governance beyond appointments alone.
We next asked about funding to support IT accessibility services. Despite 53 percent of CIOs reporting having funding for digital accessibility initiatives, open-ended responses indicate that funding is rarely stable or centralized, a sentiment also echoed in last year’s CIO survey. CIOs indicate reliance on a mix of temporary funding methods, including:
- General operational funds
- One-time appropriations
- Indirect cost recovery
- Project-embedded funds
- Short multi-year allocations
Even states funded with more structured support indicate limitations such as narrow program scopes, access only to platform-level tools or insufficient funding to cover scanning but not full remediation or staffing shortages. Some respondents noted being denied funding altogether based on citizen-engagement pools, while others are preparing for immediate funding decreases as DOJ Final Rule compliance budgets near their end. Sustaining and scaling enterprise accessibility requires consistent funding and resources, especially as CIOs continue to develop relationships with CAOs to build more robust programs.


Most states (78 percent) report that their 2024 DOJ Final Rule on Web and Mobile App Accessibility compliance plan is under implementation, which is consistent with the extension provided by the DOJ. Open-ended responses provide more details, implying that the term “compliance” is being interpreted differently nationwide. Some states describe decentralized environments making it hard to quantify completion, while others who say they have largely completed plan implementation are still working to close significant gaps.
While initially taken as positive, some CIOs indicated the final rule extension may have decreased urgency and momentum, further complicated by vendor resistance and self-reported progress that is not verified. States with more mature frameworks also report struggling with minimizing agency-driven compliance over unified enterprise approaches, a common challenge in federated IT governance models. Setting enterprise standards, employee training, procurement reviews, sharing resources and creating remediation pipelines are all common ways CIOs support digital accessibility efforts across the state. However, considering other findings, execution is largely decentralized; CIOs act as conveners or coordinators while agencies choose whether to participate. A handful of CIOs can implement advanced practices, including AI-assisted remediation, accessibility-by-design frameworks and unified platforms/resources. Overall, CIO organizations are highly involved in supporting digital accessibility programs but must do so strategically when limited by operational capacity and resource constraints.
The top CIO accessibility priorities (shown in graphic below) not only reflect DOJ Final Rule compliance mandates but also improve areas where digital accessibility is a key component in the public-service mission of state IT. CIOs have a unique opportunity to emphasize the impact of the work alongside the compliance narrative. Framing priorities as investments in more citizen-centered digital services strengthens the enterprise case for digital accessibility and increases leadership buy-in.
Top CIO Accessibility Priorities
Remediating PDFs and other documents (72)
Remediating digital citizen services (68%)
Remediating legacy systems (46%)
| Using AI to enhance digital accessibility efforts | 44% |
| Expanding accessibility while maintaining privacy and cybersecurity | 38% |
| Rebuilding websites | 38% |
| Procuring accessible technology and services/evaluating vendor readiness for new standards | 36% |
| Further embedding accessibility into the acquisition process | 34% |
| Creating a unified remediation process/pipeline | 30% |
| Responding to user complaints, feedback and potential litigation claims | 18% |
| Expanding the digital accessibility workforce for the state | 14% |
| Supporting local entities as they work to reach their deadline | 10% |
| Securing funding to better support digital accessibility initiatives | 10% |
Source: The 2026 NASCIO State CIO Survey
We next asked CIOs about their efforts to support digital accessibility with local entities. Support remains limited in scale and capacity with only 35 percent of CIO organizations reporting that they are assisting local governments.
CIO organizations are limited by operational, budgetary and staffing constraints but are still collaborating with local governments. Common state-local collaboration methods for digital accessibility initiatives include:
- Public forums
- Summits at the state capital
- Shared training resources
- Statewide contracts for tools and services (sometimes limited to optional agency participation)
- Adhoc guidance from ADA officers

CIOs noted that working with local governments can sometimes expose knowledge and technology gaps, as local leaders may be working with outdated technology or unaware of how to implement more complex technical standards. More mature states offering support utilize centralized platforms, hosting hundreds of local websites, statewide scanning tools and robust programs that centralize information sharing, resources and compliance support. However, these advanced models are the exception; most states cannot offer local support in any capacity.
For an in-depth look at the status of digital accessibility in states, see NASCIO’s inaugural State Chief Digital Accessibility Officer Survey.
Acquisition
Current CIO acquisition perspectives imply that master contracts, preapproved vendor pools and cooperative agreements are core components of the procurement lifecycle. These mechanisms have been refined over years to give the CIO greater control over risk, enforce security standards and maintain relationships with vendors who reliably meet expectations. This maturity may explain why the least commonly used acquisition components nationwide are adopting flexible terms and conditions and transitioning to AI-driven procurement automation. Acquisition pipelines are intentionally built to include nuance and guardrails. Loosening terms and conditions or fully automating procurement with AI could create issues with interpreting and implementing enterprise standards.
Technology Acquisition Components
respondents allowed to make multiple selections
98%
Master contracts
90%
Preapproved vendor pools
80%
Cooperative agreements
| Leveraging enterprise architecture | 54% |
| Negotiating with vendors in the pre-award phase | 44% |
| Streamlining of approvals and rapid purchasing | 40% |
| Digitization and automation of procurement processes and procedures | 34% |
| Greater transparency in vendor management | 32% |
| Adopting more flexible terms and conditions | 18% |
| Using AI to automate procurement processes | 10% |
Source: The 2026 NASCIO State CIO Survey
Similarly, full integration of AI into the acquisition process is limited but important. Most states indicate no use of AI at any stage of the acquisition process, with a smaller group cautiously piloting use cases. Pilots center around drafting request for proposal language, summarizing vendor responses, contract and statement of work reviews and market research. Even among the few states using more advanced strategies like agentic review systems or in-house AI platforms, accountability, transparency and legal review are critical. Generally, CIOs are in the early stages of using AI to reduce administrative burden, but not to interfere with judgment and risk-sensitive decisions.
After years of progress moving away from this practice, a number of states still allow unlimited liability contracts, something NASCIO has advocated for eliminating for over a decade. Many states reported in this survey that limits in IT contracts are often structured around contract value, fixed caps, insurance-based ceilings or case-by-case evaluations with legal and risk representatives. Statutory constraints, sovereign immunity rules and categorical prohibitions also inform limits. A similar sentiment is shared in performance-bond practices; only 18 percent require them, with most states using selective, risk-based bonding for large and/or critical IT projects. Other states rely on retainage clauses, service-level agreements or procurement office judgement in place of standard requirements. This further underscores CIO organizations’ preferences of acquisition systems that allow modification to projects, not one solution for multiple needs.
List of States and Territories Participating in the Survey
- State of Alabama
Daniel Urquhart
Secretary of Information Technology - State of Alaska
Bill Smith
Chief Information Officer - State of Arizona
J.R. Sloan
State Chief Information Officer - State of Arkansas
Jay Harton
Director and Chief Technology Officer - State of California
Chris Given
Chief Information Officer and Director - State of Colorado
Sarah Tuneberg
Chief Information Officer and Executive Director - State of Connecticut
Mark Raymond
Chief Information Officer - State of Delaware
Robert Osmond
Chief Information Officer - District of Columbia
Stephen Miller
Chief Technology Officer - State of Florida
Warren Sponholtz
Chief Information Officer - State of Georgia
Shawnzia Thomas
State Chief Information Officer and GTA Executive Director - State of Hawai’i
Christine Sakuda
Chief Information Officer - State of Idaho
Alberto Gonzalez
Former Chief Information Officer - State of Illinois
Brandon Ragle
Secretary and State Chief Information Officer - State of Indiana
Warren Lenard
State Chief Information Officer - State of Iowa
Matt Behrens
Chief Information Officer - State of Kansas
Jeff Maxon
Chief Information Technology Officer
- Commonwealth of Kentucky
Jim Barnhart
Chief Information Officer - State of Maine
Nicholas Marquis
Chief Information Officer - State of Maryland
Katie Savage
Chief Information Officer and Secretary - Commonwealth of Massachusetts
Jason Snyder
Secretary and Chief Information Officer - State of Michigan
Eric Swanson
Chief Information Officer - State of Minnesota
Jon Eichten
Commissioner and Chief Information Officer - State of Mississippi
Craig Orgeron
Executive Director and Chief Information Officer - State of Missouri
John Laurent
Chief Information Officer - State of Montana
Kevin Gilbertson
Chief Information Officer - State of Nebraska
Matthew McCarville
State Chief Information Officer - State of Nevada
Timothy Galluzi
State Chief Information Officer - State of New Hampshire
Denis Goulet
Commissioner / Chief Information Officer - State of New Jersey
Kevin Dehmer
Chief Technology Officer - State of New Mexico
Manny Barreras
Cabinet Secretary and State Chief Information Officer - State of New York
Dru Rai
State Chief Information Officer and Director - State of North Carolina
Nate Denny
Secretary and State Chief Information Officer - State of North Dakota
Corey Mock
Chief Information Officer
- State of Ohio
Katrina Flory
State Chief Information Officer / Assistant Director - State of Oklahoma
Dan Cronin
State Chief Information Officer - State of Oregon
Terrence Woods
Chief Information Officer - Commonwealth of Pennsylvania
Bry Pardoe
Deputy Secretary and Chief Information Officer - State of Rhode Island
Brian Tardiff
Chief Digital Officer and Chief Information Officer - State of South Carolina
Nathan Hogue
Chief Information Officer - State of South Dakota
Neal Nachtigall
Commissioner and State Chief Information Officer - State of Tennessee
Kristin Darby
Chief Information Officer - State of Texas
Tony Sauerhoff
Executive Director and State Chief Information Officer - U.S. Virgin Islands
Rupert Ross
Director and Chief Information Officer - State of Utah
Alan Fuller
Chief Information Officer - State of Vermont
Denise Reilly-Hughes
Secretary and State CIO - Commonwealth of Virginia
Michael Watson
State Chief Information Officer - State of Washington
William Kehoe
Director and State Chief Information Officer - State of West Virginia
Heather Abbott
Chief Information Officer - State of Wisconsin
Trina Zanow
Chief Information Officer - State of Wyoming
Jeff Clines
Director, Enterprise Technology Services and CIO
Authors and Contributors
- Amy Glasscock, CIPM, Director, Innovation and Emerging Issues
- Emily Lane, CAE, Director of Experience and Engagement
- Eric Sweden, MSIH, MBA, CGCIO, Director, Enterprise Architecture and Governance
- Alex Whitaker, Director of Government Affairs
- Kalea Young-Gibson, Senior Policy Analyst
