Technology Trends Reshaping State Regulatory Agencies

A new NASCIO State CIO Survey reveals technology trends that impact regulatory agencies from AI and cybersecurity to digital services and system modernization. The 2026 NASCIO State CIO Survey, The State CIO in Motion: Priorities, Pressures and Progress, published September 28, offers insights from 51 state and territory chief information officers on issues shaping state technology leadership. Data shows the rapid expansion of AI governance, with 98% of states using enterprise policies and procedures for AI development and use, up from 76% in 2025. Procurement terms and contract provisions for generative AI rose from 41% to 61%. The report also found that 64% of state CIOs see agentic AI as the “most impactful emerging technology” over the next two to three years, compared with 14% for GenAI. Most CIOs also highlighted critical infrastructure cyber protection as an are of high concern, with one CIO stating that “If your concerns are not significant, you need to pay more attention.”

Drivers of AI Governance

When asked to respond to the drivers of AI governance in their states, answers included:

  • Business/customer needs: 82%
  • State enterprise architecture: 73%
  • State cybersecurity road map: 71%
  • Executive or legislative mandates: 55%
  • Other: 8%

Data Security Strategies for Regulatory Agencies

A recent GovRAMP webinar focused on data classification as the starting point for informed cybersecurity. From Data to Risk: A Practical Guide to Data Classification and Scope, recorded September 22, featured industry leaders, including State of Minnesota CISO John Israel, as well as GovRAMP Executive Director Leah McGrath. Speakers stressed the need for ongoing data governance; they encouraged regular communication between agencies and technology providers to ensure security requirements keep pace with modernization efforts, including the addition of AI tools. As vendors embed new technology, Israel said, “We’ve got to come back and reassess and add that extra pillar that’s in our governance review process to assess and make sure the product is still meeting our compliance guidelines.”

The webinar paired types of data with the appropriate level of GovRAMP security. For example, GovRAMP best practices for restricted data require Authorized status, while public data requires the Security Snapshot. The webinar gave viewers three practical outcomes for the webinar; these included: identify the stakeholders involved in data classification, understand how classification shapes security and procurement requirements, and recognize when changes in data or scope require reassessment.

Best Practices for Regulatory Agencies from the Top Digital States

Government Technology’s 2026 Digital States Survey, released Sept. 24, grades states on their use of technology and highlights the practices of the 11 states that earned an “A.” The results show growing adoption of AI and evolving cybersecurity strategies across state government. Cybersecurity ranks as the number one priority for states, followed by collaboration and shared services, AI and machine learning, budget and cost control and constituent engagement and experience. “But perhaps the clearest theme emerging from the 2026 results is the increasingly interconnected nature of the work,” the authors said. “AI is changing cybersecurity, cybersecurity is shaping modernization, federal policy is influencing technology investment, and better data is becoming a prerequisite for nearly all of it.” The survey also found that states increasingly incorporate AI and automation into cybersecurity operations. Ohio, for example, now uses an AI-driven security ecosystem to automate and coordinate elements of cyber defense.

Time to Modernize

GL Solutions helps your regulatory agency run, grow and adapt with modern software and automation designed to address your agency’s biggest challenges. GL Solutions embeds AI into regulatory agency workflows in GL Suite, giving staff practical, policy-driven support that boosts efficiency, improves consistency and advances modernization—while keeping agency control and accountability at the forefront. Contact us to learn more.