State chief information officers (CIOs) are preparing for growing disruption from artificial intelligence (AI), cybersecurity threats, workforce shortages, and rising demand for digital services, according to the National Association of State Chief Information Officers’ 2026 State CIO Survey.
The survey gathered responses from 51 state and territory CIOs on eight technology and management topics. Sixty-eight percent said they expect increased turbulence and disruption in the state CIO role and organization over the next five years, while 22% said maybe and 10% said no.
“With 36 gubernatorial elections this year, I suspect 2027 will bring about lots of changes in the state CIO world,” NASCIO Executive Director Doug Robinson said in a Sept. 28 press release. “But one thing we know for certain is that the demands on state CIOs won’t slow down. The rapid evolution of artificial intelligence, demands for digital services and expansion of enterprise portfolios will continue to reshape their roles.”
AI is already reshaping state CIO roles. The survey found that 98% of states have implemented enterprise policies and procedures for AI development and use, up from 76% in 2025. Meanwhile, 61% of states have adopted procurement terms and contract provisions for generative AI, up from 41% last year.
AI activity is also moving beyond experimentation. Ninety-four percent of respondents reported generative AI pilots, 92% reported proofs of concept, and 82% said they have AI projects in production. Thirty-five percent reported enterprise-scale projects across the executive branch.
Agentic AI emerged as the technology state CIOs expect to have the greatest impact over the next two to three years. Sixty-four percent selected agentic AI, compared with 14% for generative AI and 10% for quantum computing.
Cybersecurity is another major concern. Eighty-eight percent of state CIOs identified the threat level of critical infrastructure cybersecurity attacks as an area of high concern, while the remaining respondents rated it a medium concern.
Critical infrastructure threats span communications networks, electric grids, water and wastewater systems, data centers, hospitals, and oil pipelines. Seventy-three percent of CIOs said critical infrastructure cybersecurity protection is part of their whole-of-state cybersecurity plans.
The survey found that states are extending cyber services beyond executive branch agencies. Fifty-five percent of CIOs said they provide services to local governments, public libraries, and special districts, while 53% assist K-12 school districts. However, only 49% reported having funding to support local entities with critical infrastructure cybersecurity protection.
Dave Stroth, area vice president for U.S. SLED at Elastic, told MeriTalk that the findings reflect a changing cyber threat environment.
“Adversaries attacking state and local government agencies and critical infrastructure now use AI to launch attacks in record time, forcing defenders to measure response in seconds,” Stroth said. “The only way to match the speed of AI-driven threats is with agentic security operations.”
Stroth said AI is also changing how governments respond to those threats, including through more automated security operations center (SOC) capabilities.
“This isn’t about removing people. It’s about making sure human analysts aren’t overwhelmed and drowning in alert noise,” he added.
Additionally, the survey points to persistent funding and workforce pressures. Only 28% of CIOs reported dedicated funding for AI initiatives, while 66% cited inadequate funding and budgets as a major challenge to meeting demand for citizen digital services.