What the ranking actually says
For the first time since the National Association of State Chief Information Officers began tracking annual priorities, artificial intelligence has claimed the top spot. Cybersecurity held that position for twelve consecutive years — a reflection of how decisively risk-driven state IT has operated since the breach waves of the early 2010s. Its displacement is not a verdict that cybersecurity is solved; it ranked second on the 2026 list, and the governance, workforce, and third-party risk challenges that kept it at the top are unresolved.
For CIOs, the ranking raises a practical budget question: which capabilities will the state build, who will evaluate them and what will it cost to keep them working?
Make the dependencies explicit
NASCIO frames the AI priority around governance and policies, security and privacy, workforce skills, data quality, ethical use, and overall adoption. Those responsibilities depend on one another. Governance should identify the intended use and the data used for training where applicable, retrieval, testing and operation; not every state AI deployment trains its own model.
You cannot evaluate data quality without the infrastructure to audit it. And you cannot execute either function without the workforce to staff it. Parallel work streams can be effective if their dependencies are explicit and someone owns the evidence required before deployment. Otherwise a framework can reach approval before the evaluators or monitoring capability exist.
Treat data readiness as use-case specific
Data quality is a constraint worth making explicit. Many legacy program systems were designed for transactions and reporting, not the specific AI use now proposed. A Medicaid eligibility platform may predate newer interoperability mandates. Employment and wage data collected for different statutory purposes can carry inconsistent definitions of the same concepts. Benefits enrollment may use identifier schemes that were not designed to reconcile across programs. The consequence is that when a program office asks to deploy an AI model, a necessary question — are the development, evaluation and operational data representative of the population affected? — surfaces integration debt that was invisible until the AI use case forced it into the open.
AI is, in this sense, functioning as a quality audit on state data architecture. States that address the underlying integration debt directly will build something that outlasts the specific model. States that paper over it with governance language will accumulate technical debt in a new form.
Provide evaluation capacity agencies can use
Workforce is the compounding constraint. The skills required to govern AI seriously — reading model documentation with informed skepticism, identifying statistical bias in outcomes data, monitoring model drift in deployed systems — can be difficult to recruit under public-sector compensation and classification constraints. A state CIO who is serious about AI governance needs either staff who can do this work or a shared service arrangement that delivers the capability to agency programs that cannot afford to develop it independently.
The model is not new. The shared-service pattern also appears in functions such as GIS, human resources and security operations. The argument for extending that pattern to AI evaluation is exactly the same: the function is too specialized and too costly to replicate in every agency, but not replicating it at all leaves individual programs without the capacity to know whether what they are deploying is working as intended.
Put recurring governance into the budget
The budget makes these choices concrete, and NASCIO's number three priority — budget and fiscal management — names the binding variable explicitly. Building AI governance capacity costs money: dedicated staffing for governance functions, shared infrastructure for model evaluation and monitoring, sustained investment in technical upskilling. These are multi-year commitments in an environment where discretionary IT budgets are under continuous pressure and where each state must assess its own fiscal position. The CIOs who will make the AI priority real are not those who published an AI strategy — publication alone does not demonstrate operational capacity — but those who secured a budget line for AI governance in the next cycle that did not require cannibalizing an operating system.
The organizational test is not whether a CIO named AI as a priority. It is whether the FY2027 budget request reflects what governing it actually costs.
Judge the operating model, not the policy document
A credible program should be judged on sequencing as well as policy language. It should address integration debt before scaling AI programs because governance without clean data is governance over noise. It should establish shared AI evaluation functions in the CIO's office or in a cross-agency structure, rather than expecting each agency to independently staff a capability some cannot staff independently. And it should support honest workforce conversations: what classifications attract people who can do this work, what the agency can offer that large technology employers cannot, and how contracted vendors are held accountable for what their models actually deliver in production.
The NASCIO list is a reliable indicator of what state CIOs want to be responsible for. Whether AI at number one becomes a real accountability standard or a new category in which well-intentioned frameworks produce no discernible change depends entirely on whether the institutional machinery gets built to back it up.
Turn the priority into a release decision
- Define one outcome and its limits. Identify the decision or task being improved, the people affected and the errors the program cannot tolerate. Establish a non-AI baseline for comparison.
- Test the actual data path. Review training where relevant, retrieval sources, test sets and production inputs. Check representativeness, quality, permissions and retention separately.
- Name the evaluators. Identify technical, security, privacy, program and accessibility reviewers. State which evidence they need and who resolves disagreements before deployment.
- Budget the recurring work. Include monitoring, revalidation after vendor changes, incident response, resident correction channels and staff development. A funded pilot is not a funded service.
- Use a release decision record. Document baseline results, remaining risks, approval, rollback conditions and the next review date. Stop or narrow a use case when the required evidence is missing.
What to measure
- Evaluation coverage: deployments with a representative test set, documented baseline and named reviewer.
- Change control: vendor or model changes detected and reassessed before they affect consequential use.
- Operating capacity: recurring review work funded and staffed, with a backup for each critical role.
Sources and further reading
- NASCIO 2026 priority list — AI first and cybersecurity's preceding twelve-year run
- NASCIO agentic AI report — government AI governance and evolving autonomy context
Spartan X's AI consulting, engineering and cybersecurity disciplines support the less visible work behind an AI priority: defining a suitable use, evaluating it and putting the controls and ownership in place to sustain it.



