,

The 2026 NASCIO State CIO Survey | The State CIO in Motion: Priorities, Pressures and Progress

NASCIO Contacts: Doug Robinson, Executive Director and Meredith Ward, Deputy Executive Director

The 2026 NASCIO State CIO Survey, The State CIO in Motion: Priorities, Pressures and Progress, captures insights from 51 state and territory chief information officers on the issues shaping state technology leadership. The survey explores how CIOs are navigating growing demands around digital services, technology investment governance, critical infrastructure cybersecurity, data center strategy, artificial intelligence, IT accessibility and acquisition. Findings point to a state CIO role that is increasingly focused on enterprise leadership, cross-government collaboration and measurable public value, while also confronting workforce pressures, funding constraints, rapidly evolving technologies and rising expectations for secure, accessible and modern government services.

The 2026 NASCIO State CIO Survey | The State CIO in Motion: Priorities, Pressures and Progress

Table of Contents 

  1. Executive Summary
  2. CIO Organization Advice from the Trenches
  3. Digital Services Transformation
  4. Technology Investment Governance and Management
  5. Critical Infrastructure Cybersecurity Protection  
  6. Data Center Strategy
  7. Artificial Intelligence and Emerging Technology
  8. IT Accessibility 
  9. Acquisition 
  10. List of Participating States and Territories

Executive Summary  

You have now arrived at the 2026 State CIO Survey, our 17th edition. Fifty-one state and territory chief information officers (CIOs) answered approximately 40 questions on eight topics in the summer of 2026. This year’s survey also includes responses collected from many open-ended questions and state CIOs were, as usual, generous with their time and thoughts. Next year could bring significant change in the state CIO world as there are 36 gubernatorial elections. CIOs gave us their best advice for the likely new crop of CIOs coming in 2027 as a result of those elections. We asked CIOs about some evergreen topics like artificial intelligence (AI) (yes AI has become evergreen), digital government services and technology investment management. We also asked some new questions about critical infrastructure cyber protection and data centers—do state CIOs have a role to play in the current public debate about data centers? Read the report to find out! 

CIO Organization Advice from the Trenches  

As happens every four years or so, in November 2026 there will be many gubernatorial elections—36 to be exact. This will likely bring many new state CIOs in 2027, which means we thought now is the best time to ask current state CIOs for their words of wisdom. We first asked what the strategic business role of the state CIO is. The responses we received can be summed up by saying that the state CIO has evolved into an enterprise business leader, not only a technology operator.  

State CIOs told us that operational excellence remains the foundation for transformation. One CIO advised new CIOs to, “Ensure that the state technologies run smoothly since you cannot innovate in the middle of operational chaos.” Additionally, CIOs told us that the role requires balancing immediate demands with long-term modernization within the lightning speed pace that technology is evolving. “The CIO is a chief problem solver, as technology is ingrained into every level of business,” another CIO told us.  

Not surprisingly, when describing the role of the state CIO, the advice was also heavy on the importance of interpersonal skills (we used to call this “soft” skills). The CIO must bridge fragmented government silos and build cross-boundary relationships. One CIO told us, “[The CIO is a] communicator, connector and must ultimately find ways to remove any pain related to getting business done and visions reached. Certainly, securely and transparently.” Unsurprisingly, CIOs talked about the necessity of relationship building and communication (both with others and communicating value) as central keys to success. As technology is a part of almost every facet of government these days, CIOs told us that it is crucial that, “A new CIO must sit at the leadership table, not in the basement.”  

State CIOs are now operating in a more uncertain environment with the devolution of federal program administration, cost shifts and instability. With these changes, demands on the states are increasing and citizen expectations are as well. AI has certainly added pressure as a prominent disruptor to the status quo.  We asked CIOs if they anticipate increased turbulence and disruption in the state CIO role and organization over the next five years and 68 percent said yes, 22 percent maybe and 10 percent no.  

Of course, we couldn’t resist asking CIOs to elaborate and they told us that higher public expectations, artificial intelligence, the growth and increasing sophistication of cyber threats, aging legacy systems and emerging technologies will continue to create operational and strategic risk. One state CIO framed it like this: “The state CIO is being asked to move faster while also improving security, accessibility, resilience, fiscal discipline and transparency.” Indeed, CIOs will be asked to move faster while managing greater constraints, thus making it harder for CIOs to deliver services at the pace expected. One CIO said, “We are reaching a point where traditional approaches (planning, budgeting) need much shorter cycles than our processes allow. I don’t see any set of circumstances where the state CIO job gets easier.” 

One disruptor that CIOs told us they are increasingly facing is that technology decisions are becoming more political and public facing. Issues such as AI use, surveillance concerns, data center energy and water demands, accessibility, transparency and resident expectations are pushing CIO decisions into broader policy and public trust conversations. While AI is seen as a dominant disruptive force, it is also an opportunity and a source of pressure, reshaping service delivery, workforce needs, governance, risk management and the definition of technology work itself.  

One CIO described the state CIO office as being on a “workforce cliff,” as retirements, loss of institutional knowledge and changing skill requirements are expected to challenge CIO organizations as they try to modernize and maintain critical services. The same CIO continued, “The people who hold the institutional knowledge of our legacy systems are retiring, the pipeline behind them is thin and AI is simultaneously redefining what an IT job even is.”  

We had a hunch that CIOs would want to talk about their technology workforce, so we asked how they are cultivating the future CIO organization workforce. While state CIOs are turning to a whole host of strategies and upskilling, investing in training and establishing talent pipelines were the most chosen.  

We also gave CIOs a hypothetical magic wand and asked what one thing they would change about the CIO position in their state. Many CIOs continued their calls for a move away from the inflexible chargeback model. Respondents repeatedly pointed to the need for more sustainable enterprise funding models in order to create dedicated funding for innovation, cybersecurity and transformation. CIOs also stressed the importance of cybersecurity and continue to value a whole-of-state cybersecurity model. CIOs told us that the existing procurement laws and processes remain a barrier to speed and modernization. Reducing procurement timelines and friction was identified as a key change that would help CIOs deliver more quickly and effectively. 

Upskilling current employees

Investing in training

Establishing talent pipelines

Succession planning

Partnering with higher education

Source: The 2026 NASCIO State CIO Survey

Even though we gave state CIOs a make-believe magic wand, in the real world, the role continues to be constrained by capacity and time. When asked what one thing they would change, one CIO said they wished for “More hours in the day—so many opportunities to improve things.” 

We also had a hunch that responses to this section would include the good, the bad and the uncertain, so we wanted to end on a high note. We asked current state CIOs to give their best advice on the role for the next wave of state CIOs. They stressed the need to be a business leader and public servant. One told us, “Most importantly, remember that the purpose of technology in state government is not technology itself. The purpose is better service, better decisions, better stewardship and stronger public trust.” Another said, “Be humble. Be vulnerable. Be human.” 

CIOs talked about the importance of building relationships and coalitions before driving change to create lasting impact:  

CIOs made it clear that there are certain things that can’t be compromised: “Make the technology organization easier to work with, but also make clear that enterprise standards, security, accessibility, architecture and fiscal discipline are not optional.” However, perfection isn’t attainable: “There is no ‘done.’ There is only ‘better.’ Celebrate when you get better.” 

CIOs talked about the importance of leading now: “Always lead with value creation and capture. Don’t have a grand plan that creates value five years from now (you likely won’t be around!). Have a long-range plan but generate and capture value at least every six months.” In the same spirit of planning for the future, another CIO told us to, “Always be in the business of succession planning. We need leaders willing to take risks, bring in the best talent and let each individual contribute at their maximum rate and then move on to make room for the next wave. Like shark’s teeth.” 

To close out this section, we will add a bit of advice for new CIOs from NASCIO: remember you are not alone. The NASCIO community is made up of current and former state technology folks who are always willing to listen, help and support.  

Digital Services Transformation  

Ensuring that citizens have access to digital services has been a key component of nearly all state efforts to modernize and improve their IT service offerings. States have invested in secure online portals, mobile applications, digital identity solutions and have modernized the systems that allow citizens to access services anytime and from anywhere. Doing so, however, requires a holistic mindset. As one CIO put it, “States need to think beyond individual applications and toward common capabilities such as identity, payment, notification, data exchange, accessibility, cybersecurity and cloud-enabled platforms. The real opportunity is to create digital services that are secure, accessible, measurable and easier for citizens to use across agency boundaries.” 

Despite the enthusiasm for digital transformation, states may be limited by a number of factors in expanding their offerings. As with many areas of IT investment, securing adequate funding to assist in digital transformation has been difficult. States are about evenly split on having dedicated funding for advancing citizen digital services (55 percent do; 45 percent do not). Of those who responded “yes,” they listed several factors that continue to constrict funding for digital services, including:  

  • Long-term state budget uncertainty 
  • Funding for digital transformation being fragmented across many agencies 
  • Technology emergencies that require immediate resources 
  • Being able to pay for improvements only from one-time funding sources  
  • Demand growing faster than offerings can reasonably be expanded 
  • Management of and complexities with vendor relationships 

When asked how the CIO organization is approaching business relationship management (BRM) to assist with the modernization of digital service delivery, survey participants cited focusing on customer relationship management as the top response (86 percent). Additionally, CIOs highlighted other approaches.

Overall, the shift toward digital services has altered how many CIO offices approach BRM. In a number of instances, CIOs were drastically rethinking their BRM functions or standing up entirely new ones that had not previously existed. A common theme of the new and improved BRM functions was to instill an ability to both tailor needs to each agency and to respond rapidly to new requests.  

We also asked CIOs about major challenges in meeting the demand for citizen digital services. While CIOs identified it as the top obstacle, funding alone is not the only hindrance to modernizing digital services. One CIO stated that while funding was an issue, “skills, abilities, capacity and trust all loom larger than funding.”  

Major Challenges in Meeting Demand for Citizen Digital Services

respondents selected top 3

Lack of adequate funding and budget to balance immediate public needs with future critical investment (66%)

Lack of trust in shared digital solution provisioning, coordination and effective support for digital solution offerings (32%)

Workforce skills and capability constraints to deliver and implement digital services (28%)

Lack of organizational agility/flexibility26%
No dedicated digital services team26%
Data and information quality constraints26%
Inability to envision and operationalize new ways of providing government services22%
Citizen expectations exceed organizational capabilities16%
Lack of internal willingness to take risks or embrace innovation16%
Lack of strategy and vision to implement12%
Regulatory policies and procedures present roadblocks to innovation8%

Source: The 2026 NASCIO State CIO Survey

Respondents also cited procurement rules, AI-related security challenges and increased cybersecurity attacks, time constraints, problems in pivoting to new missions and difficulty in understanding what the public actually wants from digital government. One CIO also identified the structure of government itself as a key obstacle in moving more services online: 

Finally in this section, we asked respondents how the requirement to use the .gov domain is established across state executive branch agencies. Sixty-six (66) percent of CIOs said it is required by CIO directive or policy, while 38 percent said it is governed by the state’s enterprise architecture.  

Policies around .gov adoption vary widely among states, but there is a broad consensus that .gov adoption is critical for cybersecurity protection, ensuring public trust and establishing clear authority. NASCIO consistently advocates for greater adoption of the .gov domain because it increases both cybersecurity and digital trust.  

Technology Investment Governance and Management  

As technology spending continues to grow across state government, CIOs are under increasing pressure to ensure that investments support statewide priorities, deliver measurable value and responsibly steward public resources. Effective IT investment governance provides the structure for evaluating competing priorities, balancing enterprise and agency needs and directing limited resources toward initiatives that advance strategic outcomes. Understanding how states organize these governance practices offers insight into the evolving role of the state CIO in enterprise decision-making. 

Most states are employing more than one approach to IT investment governance. This demonstrates the complexity inherent in IT investment governance and the level of effort state CIOs are putting forth to ensure effective investment in information technology. Rather than relying on a single approval authority or governance mechanism, CIO organizations are combining strategic alignment, governance boards, formal policies, staged investment reviews and collaborative budget oversight into integrated governance models. The four most common approaches employed are:  

  • Alignment between IT spending decisions and statewide priorities, outcomes and mandates  
  • Enterprise governance review and approval board, committee or council 
  • Formal IT investment governance directives or policies 
  • A stage-gate oversight process for investment approvals

State Approaches to IT Investment Governance

respondents selected top 3

Alignment between IT spending decisions and statewide priorities, outcomes and mandates (61%)

Enterprise governance review and approval board, committee or council (53%)

Formal IT investment governance directives or policies (53%)

A stage-gate oversight process for investment approvals47%
Shared approval authority with the state budget office (joint sign-off)39%
Dedicated governance or specialized funding for legacy modernization35%
Direct CIO office approval agency of IT budget request29%
Use metrics and key performance indicators to assess IT value29%
CIO office only advises the state budget office on agency IT requests28%
Using a recognized framework to guide investments26%
CIO office has no formal role in agency IT budget requests12%

Source: The 2026 NASCIO State CIO Survey

Next in this section, we asked about frameworks and disciplines used by the CIO organization to guide and measure the cost of technology. State CIOs increasingly rely on established voluntary frameworks such as NIST, reflecting the continued importance of cybersecurity and risk management in technology planning. They also rely on enterprise portfolio management, underscoring the growing emphasis on enterprise planning, investment governance and aligning technology decisions with statewide priorities. Together, these approaches can improve investment decisions, strengthen governance and provide a better understanding of the cost and value of technology. These frameworks provide common terminology, structured processes and repeatable practices for evaluating investments, managing enterprise portfolios and aligning technology with business priorities.  

Frameworks and Disciplines Used by the CIO organization to Guide and Measure the Cost of Technology

respondents allowed to make multiple selections

NIST frameworks (57%)

Enterprise Portfolio Management (EPM) (51%)

Enterprise and business architecture (47%)

IT investment management45%
ITIL (Information Technology Infrastructure Library)41%
Activity-based costing/management39%
FinOps37%
Technology Business Management (TBM)28%
COBIT (Control Objectives for Information Technology)8%
ISO/IEC 38500 (the international standard for IT governance)8%
None8%

Source: The 2026 NASCIO State CIO Survey

As technology environments become more complex, the use of multiple complementary disciplines and frameworks enables CIO organizations to balance operational excellence, financial stewardship and strategic planning. The findings also suggest that states are blending strategic, operational and financial disciplines to support enterprise decision-making. Rather than competing approaches, these frameworks appear to serve complementary roles across the technology management life cycle. 

To close out this section, we asked a few open-ended questions starting with how rates are established in a chargeback model. As enterprise technology services continue to expand, CIO organizations are increasingly expected to recover costs in ways that are transparent, equitable and sustainable. Chargeback and fee-for-service models have been around for decades and help fund shared technology services, but they also require governance processes that balance financial stewardship with customer expectations. The responses also demonstrate that establishing service rates has become an enterprise governance process rather than solely a financial exercise. 

Several patterns emerged from the responses:  

  • Most states review rates annually, while others align reviews with biennial budget cycles or conduct periodic variance analyses 
  • Rate review committees, governance boards, budget offices and legislative approval frequently play a role in the rate-setting approval process 
  • Most states invite agency participation through governance committees, formal review processes or ongoing collaboration, although the level of participation varies 
  • Several states described moving toward hybrid funding models that combine enterprise appropriations with traditional chargeback mechanisms 

Finally, several responses suggest that states are beginning to rethink traditional chargeback models. Rather than relying exclusively on direct cost recovery, some respondents described hybrid approaches that combine enterprise-funded shared services with direct billing for specialized services. These approaches seek to improve cost predictability, reduce administrative complexity and better support enterprise capabilities such as cybersecurity, digital platforms and modernization initiatives. 

The final question in this section was about measuring the value of technology. As technology spending becomes an increasingly significant component of state government operations, CIO organizations face growing expectations to demonstrate the value of technology investments. While controlling costs remains important, state leaders are also seeking evidence that technology improves government services, reduces risk, supports agency missions and delivers meaningful outcomes for residents.  

Responses present some patterns suggesting that state CIOs are:  

  • Demonstrating business outcomes by measuring service delivery, operational efficiency, citizen experience, workforce productivity and mission outcomes 
  • Evaluating risk and resilience via cybersecurity posture, risk reduction, resilience and modernization progress 
  • Ensuring strategic alignment by connecting technology investments to statewide priorities, enterprise strategies and modernization roadmaps 
  • Measuring performance based on budgets, ROI, project delivery, utilization and consumption metrics 
  • Continuously improving by actively developing formal value measurement methodologies and enterprise metrics 

The responses also suggest that states are moving toward more comprehensive approaches to value realization. Several respondents noted the importance of reduced complexity, enterprise reuse, cloud optimization and modernization outcomes alongside traditional financial measures. As enterprise technology becomes increasingly integrated into government services, CIO organizations are seeking more meaningful ways to demonstrate how technology investments contribute to long-term public value rather than simply documenting project completion or budget performance.  We anticipate more innovative approaches for measuring value will arrive as we move into the future. 

Critical Infrastructure Cybersecurity Protection  

It is no surprise that 88 percent of surveyed state CIOs identified the threat level of critical infrastructure cybersecurity attacks as an area of high concern. These include communications networks, electric grids, water/wastewater systems, data centers, hospitals and oil pipelines.  The remaining respondents categorized the threat as a medium concern. CIOs identified numerous reasons for their concern. One stated that “in rural states the exposure is concentrated in under-resourced operational systems — small water and wastewater utilities, rural health care and the energy grid. The threat is high and the defenders are thin.”  

CIOs stated that frontier AI models, a lack of resources, geopolitical tensions and the fact that many systems were outside of their direct control as being significant causes for concern. As one respondent noted, “If your concerns are not significant, you need to pay more attention.”  

We next asked if critical infrastructure cyber protection (CICP) is part of the CIO’s whole-of-state plans and an overwhelming majority (73 percent) said yes. Of those who answered “no” to this question, many indicated that they were working toward this goal or that the responsibility to critical infrastructure incidents falls outside of their office.  

Several CIOs also provide CICP services to other entities within the state, with the top two responses being other branches of government and local entities. When elaborating on what services were provided, CIOs highlighted training, awareness, scanning, assessments and other basic services.  

CICP Services Offered Beyond Executive Branch

respondents allowed to make multiple selections

Yes, other branches57%
Yes, local governments, public libraries and special districts55%
Yes, K-12 school districts53%
Yes, higher education35%
Yes, tribal governments28%
Yes, public hospitals and health care facilities24%
No24%
Yes, public electric, water and wastewater utilities22%

Source: The 2026 NASCIO State CIO Survey

When asked about funding for CICP, about half (49 percent) have funding to support local entities. To help fill these gaps, CIOs credited partnerships with MS-ISAC, fusion centers, emergency management operations and a reliance on the State and Local Cybersecurity Grant Program (SLCGP) as critical in delivering these services. The SLCGP was identified by a number of respondents as vital to funding local entities for CICP. According to one CIO, “SLCGP funding is used to strengthen cybersecurity capabilities, improve resilience, address identified risks, enhance incident response preparedness and implement cybersecurity best practices.” Many CIOs expect that the explosion of AI will create a much greater demand and need for this type of funding.  

For an in-depth look into critical infrastructure cyber protection, see NASCIO and GDIT’s publication on this topic.  

Data Center Strategy  

With expanded AI usage across the country, data centers have become a hot topic of discussion for the public, in the media and in legislatures. However, for state CIOs, data centers and their operation, optimization and consolidation have been an area of priority for decades. We wanted to know what state plans for data center activity are in the next two to three years.  

State Plans for Data Centers in Next 2-3 Years

respondents allowed to make multiple selections

Expand use of public cloud infrastructure (73%)

Adopt a hybrid model (combination of state-owned and cloud/third-party) (55%)

Maintain current state-owned data center footprint (49%)

Downsize or right-size the state’s primary data center43%
Expand cloud use specifically for disaster recovery or business continuity41%
Consolidate agency-owned data centers under centralized CIO authority26%
Reduce the total number of agency-owned data centers26%
Migrate to a co-location facility (state equipment in a third-party facility)18%
Outsource data center operations to a 3rd-party MSP (on-premise)10%
Expand state-owned and operated data centers6%
Consolidate or reduce the number of third-party data center vendors6%
Expand use of third-party hosted data centers4%
Exit the state-owned data center model entirely (full third-party reliance)4%

Source: The 2026 NASCIO State CIO Survey

The top five responses suggest states are making moves:  

Expand use of public cloud infrastructure (73 percent). This is the highest priority for state CIOs—they want to move more infrastructure, applications, storage, backups and other workloads to public cloud infrastructure (meaning a third party, off-premise provider).  One CIO stated, “This represents the best value for dollars due to its elasticity and scalability as well as ready access to emerging technologies in secured environments.” 

Adopt a hybrid model (combination of state-owned and cloud/third-party) (55 percent). A significant number of state CIOs describe a hybrid model that combines public cloud with selected state-operated, hosted or collocated infrastructure. “A hybrid cloud strategy improves resiliency, reduces unnecessary duplication, supports agency modernization and positions the state for future digital services and AI-enabled capabilities,” according to one CIO who is prioritizing this approach. 

Maintain current state-owned data center footprint (no significant change) (49 percent). Some states plan to keep a meaningful physical data center footprint and invest in modernizing core infrastructure, improving reliability, reorganizing facilities or maintaining service quality. One CIO made the argument for this choice by saying “We are able to deliver the flexibility and extensibility of cloud at a lower cost point in most cases once the total cost of ownership in the cloud is calculated.” 

Downsize or right-size the state’s primary data center (43 percent). Many states also want to reduce the primary data center as well as the number of agency-owned/operated data centers, eliminate duplicative infrastructure, right-size local capacity or close legacy facilities. “Our top priority is vacating a legacy on-premise data center and migrating to a hosted and managed service solution,” one CIO said. 

Expand cloud use specifically for disaster recovery or business continuity (41 percent). Cloud-based disaster recovery, disaster recovery as-a-service, stronger business continuity and improved operational resilience appear repeatedly in CIO comments. According to one state CIO, “Implementing a cloud disaster recovery strategy is our top priority to drive toward a hybrid model.” 

When state CIOs were asked to estimate how much of their state’s current compute environment is on-premise in state-owned data centers, the numbers varied widely. Responses reflected that on-premise compute remains a substantial part of most state IT environments. Answers ranged from zero to 90 percent, with a median of 60 percent.  

Given recent debates stemming from public backlash against the energy use, water demands and other environmental impacts of expanding data centers to facilitate emerging AI advances, we wanted to know what role, if any, state CIOs have in this debate. Slightly more than half of CIOs described a current or expected role, including task force participation, advising governors or legislative leaders, providing technical expertise or answering questions when requested. As one CIO told us, “The CIO role is to provide balanced, practical guidance that considers economic opportunity, environmental stewardship, infrastructure readiness, cybersecurity and the long-term technology needs of the state.” 

Among CIOs who asserted they did not have a role in this debate, common explanations included that the issue is handled by economic development, environmental agencies, utilities, local government or governor’s office policy teams. A few also noted that the issue had become politically contentious and expressed reluctance to enter the debate. One state CIO commented, “This is going to be a huge deal for some state CIOs and society as a whole. Resiliency will be required!” 

Artificial Intelligence and Emerging Technology 

It’s been three and a half years since generative artificial intelligence (GenAI) was made widely available. For the first time this year, artificial intelligence (AI) made it to the number one spot on the NASCIO State CIO Top 10 Priorities list for 2026. States are finding that AI has been integrated into familiar platforms, employees are expected to use it, AI projects have expanded from pilots to scaled initiatives and we know from our own internal data that about half of states have hired someone with “AI” in their job title. The conversation has also shifted from what can AI produce (generative AI) to what can AI do (agentic AI). AI is changing how states do business and changing it at a rapid pace. 

As we have in the last two years, we asked state CIOs which action items regarding generative AI (GenAI) have been implemented in their states. The biggest shift is that almost all states have implemented enterprise policies and procedures on development and use of AI (98 percent, up from 76 percent in 2025). Two other big shifts were the number of states that have put in place procurement terms and contract provisions around GenAI (61 percent, up from 41 percent in 2025) as well as the number who have addressed transparency and accountability (61 percent, up from 41 percent in 2025). The number of states that have implemented responsible use, flexible guardrails, security and ethics stayed level (88 percent) as did the number of states that have created advisory committees and task forces (82 percent).  

What States Have Implemented for GenAI

respondents allowed to make multiple selections

98%
Enterprise policies and procedures on development and use

88%
Responsible use, flexible guardrails, security, ethics

82%
Creation of advisory committees and task forces

Adopted a governance framework79%
Inventory and documenting uses in agencies and applications77%
Procurement terms and contract provisions61%
Transparency and accountability61%
Data governance: data sources, data quality, bias, data privacy57%
Requiring disclosure by software providers49%
Impact on operations and workforce37%

Source: The 2026 NASCIO State CIO Survey

While these numbers have improved, there is still work to be done. As one state CIO said, “Virtually all options were selected with the caveat that these efforts are very early, immature and/or not strictly enforced. We still lack broad understanding and socialization of our AI policy, making enforcement and governance difficult.” 

AI governance, a critical component, has been improving as well. This year, 78 percent of state CIOs reported that they had adopted an AI governance framework (up from 65 percent in 2025). We asked state CIOs this year about the drivers of central AI governance in their state. The most popular answers were the needs of the business/customer (82 percent), the state enterprise architecture (73 percent) and the state cybersecurity roadmap (71 percent). “We went through a phase of chasing AI ‘quick wins’ in mid-2025, with modest success. The exercise taught most participants and stakeholders that meaningful efficiencies from AI require more planning and broader application,” said one state CIO. 

Given the risks of using AI in state government, this year we asked state CIOs an open-ended question about whether their organization has included safety and ethics guardrails in its AI governance, guidance and operations, and if so, how. About two-thirds of state CIOs said that they were actively incorporating safety guardrails. The most common answer was that they had put AI safety guardrails into enterprise or statewide policies. Many states also said that they are required to review AI before deploying or purchasing it and that AI safety is aligned with privacy, data protection and cybersecurity governance. “The CIO organization has an important role in helping agencies understand where AI can add value, where it introduces risk and how to move from pilots to responsible operational use,” explained one state CIO. 

Again, this year we asked CIOs what GenAI activities they have in place. Ninety-four (94) percent have pilot projects and 92 percent have proofs of concept—both have slightly higher numbers than last year. Although we did not ask about projects in production last year, this year 82 percent of states reported having projects at that stage. We also asked for the first time about enterprise-scale projects across the executive branch, with 35 percent of states reporting instances of this progress. These two new metrics indicate that states have moved beyond pilots into scaled production of AI.  

Unfortunately, dedicated funding remains a challenge as only 28 percent of CIOs report dedicated funding for AI initiatives. This is just slightly higher than the 25 percent reported in 2025. Given the high prevalence of AI in states, funding must be coming from other nondedicated sources and/or be more limited than states would like. “We still do not have dedicated funding for AI which makes it difficult to move quickly with additional pilot projects, proofs of concepts, and expanding the sandbox,” explained a state CIO. 

An important conversation among state technology leaders has been about how to measure return on investment (ROI) when it comes to AI, so we asked CIOs how they evaluate or measure the success of AI activities. Overall, the responses suggest that states are moving through a progression in how they evaluate GenAI initiatives. Early efforts tend to focus on participation—tool usage, training, employee adoption and the number of pilots launched. As programs mature, states begin measuring project-level results, including estimated time saved, workload reduction, user feedback and improvements in accuracy or service delivery. The most advanced approaches connect these results to broader business outcomes, ROI, resident value and the ability to scale across government. Across all stages, states increasingly view security, privacy, governance and responsible use as essential parts of success as well. One state CIO summed it up by saying, “The priority is not simply to experiment with AI, but to learn which use cases can be implemented responsibly and scaled where they create measurable value.” 

This is the third year we have asked if employees in the CIO’s organization are using generative AI tools in their daily work and this year 96 percent said they are! This is a big jump from just 54 percent two years ago. While not every employee in every state is using it, at least some employees have been given licenses to use GenAI at work in almost every state CIO organization. 

To learn more about the GenAI work in states, we asked about the estimated number of GenAI projects in production across the executive branch. The numbers varied widely, from “four” to “thousands.” Some CIOs had difficulty even estimating the number, saying things such as, “It’s hard to say since it’s embedded in so many activities.”  

For the first time this year, we asked the CIO if their state is using agentic AI in any state operation. Twenty-nine (29) percent said yes, 35 percent said use of agentic AI is planned and 29 percent said no (others were unsure).  

The most common application of agentic AI is in workflow and process automation. Other popular answers were IT operations, application development, coding, modernization and customer service/contact centers. The dominant application area is for automating repetitive internal work, including routing, approvals, reviews, back-office tasks, data processing, procurement and IT governance. As with GenAI, states are taking thoughtful, internal approaches with agentic AI first. “We will prove it internally, with a human accountable for every consequential action, before extending it to citizen-facing operations,” explained one state CIO. 

State CIOs clearly see a lot of potential in agentic AI. Sixty-four (64) percent said that agentic AI will be the most impactful emerging technology in the next two to three years, followed by GenAI with only 14 percent. One CIO stated, “I think the agentic AI revolution has the potential to dramatically transform government. We have spent decades building software systems with a user interface that assumes the user is a human. What happens when that is an AI agent? The process of business fundamentally needs to change.” 

Ten percent of state CIOs said that quantum computing would be most impactful, but most CIOs see it as a future development. When we asked about the status of quantum computing in their state governments, 73 percent of state CIOs said they are monitoring developments and have taken no formal action on it yet. As one state CIO put it, “We have generally been discussing quantum but there is limited impact expected so AI is prioritized.” 

Status of Quantum Computing in States

respondents allowed to make multiple selections

73%
Monitoring developments (no formal action yet)

26%
Partnering with universities or research institutions

18%
Policy discussions are underway

Engaging with federal agencies or interstate peers14%
Post-quantum cryptography/quantum-safe security initiative underway14%
Planned but not yet started12%
Advisory team or working group formed10%
No current plans8%
Budget or funding allocated for quantum-related activities6%
Quantum readiness assessment completed on operations and workforce4%
Enterprise policy or strategy established2%
Proof of concept or sandbox environment established2%
State employee awareness or training programs are underway2%

Source: The 2026 NASCIO State CIO Survey

So, what’s next? State CIOs mentioned the following themes for what they expect to focus on related to emerging technology over the next few years: 

  • Moving from pilots and experimentation to scaled, operational use 
  • Improving governance, policies, standards and responsible-use guardrails 
  • Addressing cybersecurity and AI-specific security risks and opportunities 
  • Exploring agentic AI as a major next phase 
  • Improving data readiness, governance, privacy or sovereignty 

The recurring message is that states will need to strengthen governance, cybersecurity, data, procurement, workforce readiness and cost controls at the same time they expand adoption of AI. 

IT Accessibility  

IT accessibility (sometimes abbreviated as A11y) moved from up to number six from number 10 on the 2026 State CIO Top 10, signaling national growth and understanding of digital accessibility as a core enterprise principle. The inaugural NASCIO State Accessibility Officer Survey found that 40 out of 56 (more than 70 percent) of states and territories have a state digital accessibility lead. However, there are many differences in job titles across organizational structures and reporting models. The CIO’s most critical enterprise digital accessibility leader is the chief digital accessibility officer (CAO). In this year’s state CIO survey, we found that 44 percent of states have a CAO, including four percent that report outside the CIO organization. Conversely, 46 percent of states do not have a CAO while six percent are in process of recruiting.   

Some CIOs indicated roles like “DEI director” absorb all duties of a standard CAO without the title. These findings highlight the need for broader establishment of the CAO within state IT governance beyond appointments alone.  

We next asked about funding to support IT accessibility services. Despite 53 percent of CIOs reporting having funding for digital accessibility initiatives, open-ended responses indicate that funding is rarely stable or centralized, a sentiment also echoed in last year’s CIO survey. CIOs indicate reliance on a mix of temporary funding methods, including: 

  • General operational funds 
  • One-time appropriations 
  • Indirect cost recovery 
  • Project-embedded funds 
  • Short multi-year allocations 

Even states funded with more structured support indicate limitations such as narrow program scopes, access only to platform-level tools or insufficient funding to cover scanning but not full remediation or staffing shortages. Some respondents noted being denied funding altogether based on citizen-engagement pools, while others are preparing for immediate funding decreases as DOJ Final Rule compliance budgets near their end. Sustaining and scaling enterprise accessibility requires consistent funding and resources, especially as CIOs continue to develop relationships with CAOs to build more robust programs.  

Most states (78 percent) report that their 2024 DOJ Final Rule on Web and Mobile App Accessibility compliance plan is under implementation, which is consistent with the extension provided by the DOJ. Open-ended responses provide more details, implying that the term “compliance” is being interpreted differently nationwide. Some states describe decentralized environments making it hard to quantify completion, while others who say they have largely completed plan implementation are still working to close significant gaps.  

While initially taken as positive, some CIOs indicated the final rule extension may have decreased urgency and momentum, further complicated by vendor resistance and self-reported progress that is not verified. States with more mature frameworks also report struggling with minimizing agency-driven compliance over unified enterprise approaches, a common challenge in federated IT governance models. Setting enterprise standards, employee training, procurement reviews, sharing resources and creating remediation pipelines are all common ways CIOs support digital accessibility efforts across the state. However, considering other findings, execution is largely decentralized; CIOs act as conveners or coordinators while agencies choose whether to participate. A handful of CIOs can implement advanced practices, including AI-assisted remediation, accessibility-by-design frameworks and unified platforms/resources. Overall, CIO organizations are highly involved in supporting digital accessibility programs but must do so strategically when limited by operational capacity and resource constraints.  

The top CIO accessibility priorities (shown in graphic below) not only reflect DOJ Final Rule compliance mandates but also improve areas where digital accessibility is a key component in the public-service mission of state IT. CIOs have a unique opportunity to emphasize the impact of the work alongside the compliance narrative. Framing priorities as investments in more citizen-centered digital services strengthens the enterprise case for digital accessibility and increases leadership buy-in.  

Top CIO Accessibility Priorities

Remediating PDFs and other documents (72)

Remediating digital citizen services (68%)

Remediating legacy systems (46%)

Using AI to enhance digital accessibility efforts44%
Expanding accessibility while maintaining privacy and cybersecurity38%
Rebuilding websites38%
Procuring accessible technology and services/evaluating vendor readiness for new standards36%
Further embedding accessibility into the acquisition process34%
Creating a unified remediation process/pipeline30%
Responding to user complaints, feedback and potential litigation claims18%
Expanding the digital accessibility workforce for the state14%
Supporting local entities as they work to reach their deadline10%
Securing funding to better support digital accessibility initiatives10%

Source: The 2026 NASCIO State CIO Survey

We next asked CIOs about their efforts to support digital accessibility with local entities. Support remains limited in scale and capacity with only 35 percent of CIO organizations reporting that they are assisting local governments.  

CIO organizations are limited by operational, budgetary and staffing constraints but are still collaborating with local governments. Common state-local collaboration methods for digital accessibility initiatives include: 

  • Public forums 
  • Summits at the state capital
  • Shared training resources 
  • Statewide contracts for tools and services (sometimes limited to optional agency participation) 
  • Adhoc guidance from ADA officers 

CIOs noted that working with local governments can sometimes expose knowledge and technology gaps, as local leaders may be working with outdated technology or unaware of how to implement more complex technical standards. More mature states offering support utilize centralized platforms, hosting hundreds of local websites, statewide scanning tools and robust programs that centralize information sharing, resources and compliance support. However, these advanced models are the exception; most states cannot offer local support in any capacity.  

For an in-depth look at the status of digital accessibility in states, see NASCIO’s inaugural State Chief Digital Accessibility Officer Survey.  

Acquisition  

Current CIO acquisition perspectives imply that master contracts, preapproved vendor pools and cooperative agreements are core components of the procurement lifecycle. These mechanisms have been refined over years to give the CIO greater control over risk, enforce security standards and maintain relationships with vendors who reliably meet expectations. This maturity may explain why the least commonly used acquisition components nationwide are adopting flexible terms and conditions and transitioning to AI-driven procurement automation. Acquisition pipelines are intentionally built to include nuance and guardrails. Loosening terms and conditions or fully automating procurement with AI could create issues with interpreting and implementing enterprise standards.  

Technology Acquisition Components

respondents allowed to make multiple selections

98%
Master contracts

90%
Preapproved vendor pools

80%
Cooperative agreements

Leveraging enterprise architecture54%
Negotiating with vendors in the pre-award phase44%
Streamlining of approvals and rapid purchasing40%
Digitization and automation of procurement processes and procedures34%
Greater transparency in vendor management32%
Adopting more flexible terms and conditions18%
Using AI to automate procurement processes10%

Source: The 2026 NASCIO State CIO Survey

Similarly, full integration of AI into the acquisition process is limited but important. Most states indicate no use of AI at any stage of the acquisition process, with a smaller group cautiously piloting use cases. Pilots center around drafting request for proposal language, summarizing vendor responses, contract and statement of work reviews and market research. Even among the few states using more advanced strategies like agentic review systems or in-house AI platforms, accountability, transparency and legal review are critical. Generally, CIOs are in the early stages of using AI to reduce administrative burden, but not to interfere with judgment and risk-sensitive decisions. 

After years of progress moving away from this practice, a number of states still allow unlimited liability contracts, something NASCIO has advocated for eliminating for over a decade. Many states reported in this survey that limits in IT contracts are often structured around contract value, fixed caps, insurance-based ceilings or case-by-case evaluations with legal and risk representatives. Statutory constraints, sovereign immunity rules and categorical prohibitions also inform limits. A similar sentiment is shared in performance-bond practices; only 18 percent require them, with most states using selective, risk-based bonding for large and/or critical IT projects. Other states rely on retainage clauses, service-level agreements or procurement office judgement in place of standard requirements. This further underscores CIO organizations’ preferences of acquisition systems that allow modification to projects, not one solution for multiple needs.  

List of States and Territories Participating in the Survey  

  • State of Alabama 
    Daniel Urquhart 
    Secretary of Information Technology 
  • State of Alaska 
    Bill Smith 
    Chief Information Officer  
  • State of Arizona  
    J.R. Sloan 
    State Chief Information Officer 
  • State of Arkansas  
    Jay Harton 
    Director and Chief Technology Officer 
  • State of California  
    Chris Given 
    Chief Information Officer and Director  
  • State of Colorado 
    Sarah Tuneberg 
    Chief Information Officer and Executive Director 
  • State of Connecticut 
    Mark Raymond  
    Chief Information Officer  
  • State of Delaware 
    Robert Osmond 
    Chief Information Officer 
  • District of Columbia 
    Stephen Miller 
    Chief Technology Officer 
  • State of Florida 
    Warren Sponholtz 
    Chief Information Officer  
  • State of Georgia  
    Shawnzia Thomas 
    State Chief Information Officer and GTA Executive Director 
  • State of Hawai’i 
    Christine Sakuda 
    Chief Information Officer 
  • State of Idaho  
    Alberto Gonzalez 
    Former Chief Information Officer  
  • State of Illinois 
    Brandon Ragle 
    Secretary and State Chief Information Officer 
  • State of Indiana  
    Warren Lenard 
    State Chief Information Officer  
  • State of Iowa  
    Matt Behrens 
    Chief Information Officer  
  • State of Kansas  
    Jeff Maxon 
    Chief Information Technology Officer 
  • Commonwealth of Kentucky  
    Jim Barnhart  
    Chief Information Officer  
  • State of Maine  
    Nicholas Marquis 
    Chief Information Officer  
  • State of Maryland 
    Katie Savage 
    Chief Information Officer and Secretary  
  • Commonwealth of Massachusetts  
    Jason Snyder 
    Secretary and Chief Information Officer  
  • State of Michigan  
    Eric Swanson 
    Chief Information Officer 
  • State of Minnesota 
    Jon Eichten 
    Commissioner and Chief Information Officer  
  • State of Mississippi  
    Craig Orgeron 
    Executive Director and Chief Information Officer  
  • State of Missouri  
    John Laurent 
    Chief Information Officer  
  • State of Montana  
    Kevin Gilbertson 
    Chief Information Officer  
  • State of Nebraska
    Matthew McCarville
    State Chief Information Officer 
  • State of Nevada 
    Timothy Galluzi 
    State Chief Information Officer 
  • State of New Hampshire  
    Denis Goulet  
    Commissioner / Chief Information Officer 
  • State of New Jersey 
    Kevin Dehmer 
    Chief Technology Officer 
  • State of New Mexico 
    Manny Barreras 
    Cabinet Secretary and State Chief Information Officer 
  • State of New York  
    Dru Rai 
    State Chief Information Officer and Director 
  • State of North Carolina  
    Nate Denny 
    Secretary and State Chief Information Officer 
  • State of North Dakota
    Corey Mock 
    Chief Information Officer 
  • State of Ohio  
    Katrina Flory 
    State Chief Information Officer / Assistant Director  
  • State of Oklahoma  
    Dan Cronin 
    State Chief Information Officer  
  • State of Oregon  
    Terrence Woods 
    Chief Information Officer  
  • Commonwealth of Pennsylvania  
    Bry Pardoe  
    Deputy Secretary and Chief Information Officer  
  • State of Rhode Island 
    Brian Tardiff 
    Chief Digital Officer and Chief Information Officer 
  • State of South Carolina 
    Nathan Hogue 
    Chief Information Officer 
  • State of South Dakota  
    Neal Nachtigall 
    Commissioner and State Chief Information Officer  
  • State of Tennessee  
    Kristin Darby 
    Chief Information Officer  
  • State of Texas  
    Tony Sauerhoff 
    Executive Director and State Chief Information Officer  
  • U.S. Virgin Islands 
    Rupert Ross 
    Director and Chief Information Officer  
  • State of Utah 
    Alan Fuller 
    Chief Information Officer  
  • State of Vermont  
    Denise Reilly-Hughes 
    Secretary and State CIO  
  • Commonwealth of Virginia  
    Michael Watson 
    State Chief Information Officer  
  • State of Washington 
    William Kehoe 
    Director and State Chief Information Officer 
  • State of West Virginia  
    Heather Abbott 
    Chief Information Officer  
  • State of Wisconsin  
    Trina Zanow 
    Chief Information Officer  
  • State of Wyoming 
    Jeff Clines 
    Director, Enterprise Technology Services and CIO 

Authors and Contributors  

  • Amy Glasscock, CIPM, Director, Innovation and Emerging Issues 
  • Emily Lane, CAE, Director of Experience and Engagement 
  • Eric Sweden, MSIH, MBA, CGCIO, Director, Enterprise Architecture and Governance 
  • Alex Whitaker, Director of Government Affairs  
  • Kalea Young-Gibson, Senior Policy Analyst  

Related Resources