Thinklytics

Government · 16 min read · May 2026

The 2026 Government AI Readiness Map: Federal, State, and Local

By Thinklytics Public Sector Practice, Federal, State, and Local Analytics + AI

Federal AI use cases jumped 105 percent in one year and AI dethroned cybersecurity at the top of state CIO priorities for the first time in 12 years. This is the operating brief for public-sector leaders who have to translate that signal into a 2026 plan that procurement, oversight, and the IG will all sign off on.

Does EO 14179 mean federal AI governance is gone?

No. EO 14179 rescinded EO 14110 but the underlying statutory and procurement requirements remain. M-25-22 explicitly preserves the procurement-disclosure and IP-rights provisions. NIST AI RMF and AI 600-1 are still the de-facto compliance reference. GAO inventories continue. The 94 government-wide AI requirements identified in GAO-25-107933 are still in force. What changed is the policy emphasis from precaution to acceleration. The compliance floor is still there.

The signal that should reset every public-sector AI plan

Two numbers from the back half of 2025 tell you everything about where U.S. government AI is heading in 2026. The federal government published 3,611 active AI use cases across 56 agencies in its 2025 inventory, a 105 percent year-over-year jump from 1,757 in 2024 (OMB 2025 Federal Agency AI Use Case Inventory, GitHub repository, March 2026). And NASCIO's 2026 State CIO survey put artificial intelligence at the top of state CIO priorities for the first time, ending a 12-year cybersecurity reign (NASCIO, December 2025).

That is not a tooling story. It is a budgeting and a procurement story. The Department of Defense FY2026 budget request includes a separate $13.4 billion line item for autonomy and AI systems, the first time DoD has carved out a dedicated AI budget line (MeriTalk, February 2026). The total DoD IT request was $66 billion, up $1.8 billion from FY2025 (Washington Technology, February 2026). Civilian-side, GSA's OneGov strategy executed agreements with Adobe, Anthropic, AWS, Google, Microsoft, and OpenAI in 2025 (GSA press release, August 18, 2025). And Microsoft's December 2025 FedRAMP High authorization across its full GenAI portfolio cleared the path for 2.3 million federal employees to use AI inside government cloud environments (Wedbush market wire, December 2025).

Most of that motion landed under a new policy regime. President Trump rescinded EO 14110 on his first day in office and replaced it with EO 14179, "Removing Barriers to American Leadership in AI" (January 23, 2025). OMB then issued M-25-21 ("Accelerating Federal Use of AI") and M-25-22 ("Driving Efficient Acquisition of AI in Government") on April 3, 2025, replacing the Biden-era M-24-10 and M-24-18. The two new memos require every covered agency to designate a Chief AI Officer within 60 days, file a compliance plan within 180, and apply the new procurement rules to every solicitation issued on or after September 30, 2025 (OMB M-25-22 PDF, White House).

This whitepaper is the operating brief. It maps the 2026 government AI spend, names the agencies and states that are actually shipping, lays out the procurement and risk timeline that public-sector leaders will navigate this year, and ends with a 90-day plan that procurement, the IG, and the Chief AI Officer can all defend.

Tier 1: Federal civilian agencies

The 2025 OMB inventory ranks the top federal AI buyers by use case count: HHS, NASA, VA, DOE, and DOJ (ExecutiveGov, April 2026). That order matters because it tells us which mission areas are absorbing AI fastest, which means which procurement channels are open, and which Chief AI Officer offices are setting precedent for everyone else.

The IRS is the clearest civilian-agency case study of the inflection. As of mid-2025 the IRS had 126 active AI use cases. By the time GAO published its inventory blog the count had moved to 129, up from 54 in 2024 (GAO blog, "Inside the IRS' Use of Artificial Intelligence"). That is 139 percent year-over-year growth at a single tax-administration agency. The named replacement system, the Line Anomaly Recommender (LAR), retired the legacy Discriminant Analysis System (DAS) and now scores returns by relationships among line items rather than isolated anomalies. Salesforce Agentforce was rolled into Chief Counsel, the Taxpayer Advocate, and Appeals beginning in late 2025.

CMS published the cleanest civilian ROI dollar figure of the year. CMS reported $2 billion saved since March 2025 from AI-driven fraud detection and contract oversight (ExecutiveGov, citing CMS principal deputy administrator Kim Brandt). The CMS Center for Program Integrity now runs roughly 250 fraud-detection models per day in production (FedScoop, "CMS AI fraud detection in Medicare and Medicaid programs"). For comparison, that is a higher production-model density than most Fortune 500 fraud teams.

VA was the breakout enterprise rollout of late 2025. The agency launched its ambient AI scribe in October 2025 and is expanding to all VA medical centers in 2026 (Stars and Stripes, December 15, 2025). On the back-office side, the AI eFax fix, AIEFF, has saved roughly 560 minutes per 400 community-care documents and approximately 4,000 minutes per week at one facility's fax volume (VA News, "AI tool helps VA process community care faster").

Not every civilian-agency rollout has gone the same way. SSA installed an AI fraud-detection chatbot on its national 1-800 line in early 2025 and reversed it after the system flagged only 2 potential fraud claims out of 111,000 calls (Nextgov, July 2025, citing Senate Democrats' inquiry). And DOGE-deployed AI at the VA flagged more than 2,000 contracts as nonessential, then was found to have hallucinated some flagged contract values to be orders of magnitude larger than actual (Nextgov, June 2025). Federal News Network later reported that 794 of the contract cancellations attributed to DOGE, or about one-third of the total, were expected to produce no savings (Federal News Network, February 2025). Public-sector leaders who are reading these alongside the IRS and CMS wins should treat them as the definition of the AI-readiness gap. The wins came from agencies that had clean transactional data and decade-old fraud rules to displace. The reversals came from agencies that deployed before measuring.

Tier 2: Federal defense and intelligence

The Army Enterprise Service Agreement with Palantir on July 31, 2025 was the largest single software/AI award of the year. The agreement consolidates 75 existing contracts (15 prime + 60 related) and runs up to $10 billion over 10 years (U.S. Army press release). It defines the upper bound of the federal AI-platform market.

Snowflake achieved DoD Impact Level 5 (IL5) Provisional Authorization on AWS GovCloud US-West in April 2025 (Snowflake press release). Databricks earned FedRAMP High on AWS GovCloud in February 2025 and now reports serving more than 400 public-sector customers, including roughly 80 percent of executive departments of the U.S. federal government (Databricks press release). FedRAMP, for its part, has formally prioritized authorization of AI-based cloud services for routine federal-worker use (FedRAMP AI page). The infrastructure layer for federal AI is no longer the bottleneck.

Tier 3: State and local

The 2026 NASCIO survey is the cleanest statement of where state CIOs are pointing their 2026 budgets. Artificial intelligence took the number-one spot on state CIO priorities for the first time, displacing cybersecurity which had held the top position for 12 straight years (NASCIO, December 2025). In the prior year's survey, cyber had reclaimed first and AI was second (NASCIO 2025 survey).

That priority signal is now backed by named state-level policy and budget action.

Texas signed the Texas Responsible AI Governance Act (TRAIGA) on June 22, 2025, with enforcement beginning January 1, 2026 (Norton Rose Fulbright, "The Texas Responsible AI Governance Act"). The Texas Attorney General is authorized to impose civil penalties up to $200,000 per violation alongside a 60-day cure period (Latham & Watkins, "Texas Signs Responsible AI Governance Act Into Law"). TRAIGA explicitly names the NIST AI Risk Management Framework as an affirmative defense for organizations following its practices, which converts a voluntary federal framework into a state-level compliance lever overnight.

California Governor Newsom signed Executive Order N-5-26 on March 30, 2026, directing state agencies to develop new standards for AI vendors that contract with the state. State entities are now required to complete a Generative AI Risk Assessment (SIMM 5305-F) for any planned GenAI deployment (GovTech). Pennsylvania ran a state-employee ChatGPT pilot whose final report (March 2025) cited 95 minutes per day in average employee time savings across writing, research, summarization, and IT support (PA OA Pilot Report PDF). Following the pilot, Pennsylvania expanded GenAI tools to more than 3,000 employees across 35 agencies (StateScoop). And San Francisco rolled out generative AI to roughly 2,000 city employees following a six-month pilot, with reported productivity gains of up to 5 hours per week (GovTech). New York State appointed Shreya Amin as its first Chief AI Officer in early 2025 (StateScoop).

The pattern is the same across these jurisdictions. Each one paired a named pilot with a documented productivity number, then converted that number into a procurement framework that the state CIO and the Attorney General could both stand behind. That is the template.

The 2026 procurement and risk timeline

This is the calendar that public-sector leaders should keep visible.

The OMB M-25-22 procurement clock began September 30, 2025 and is now running on every covered solicitation. Agencies are required to complete the new disclosure, performance, and IP-rights provisions on AI awards. The internal compliance burden falls on the Chief AI Officer, the Senior Procurement Executive, and the agency's Office of General Counsel.

TRAIGA enforcement began January 1, 2026 in Texas. Any AI used to make consequential decisions about Texas residents (employment, housing, financial services, healthcare, education, government services) carries the $200K-per-violation exposure unless the deploying organization can show alignment with the NIST AI RMF or another named framework as an affirmative defense.

NIST released the concept note for an AI RMF Profile on Trustworthy AI in Critical Infrastructure on April 7, 2026 (NIST). State and local utility, water, and transportation agencies should expect that profile to set the bar for their AI deployments before year-end.

NIST AI 600-1, the Generative AI Profile, is now the de-facto reference for federal GenAI risk management and the document TRAIGA points to. Every Chief AI Officer office should treat compliance with AI 600-1 as the floor.

GAO published two reports in 2025 that should sit on every public-sector AI executive's desk. GAO-25-107933 identified 94 government-wide AI requirements across 10 oversight and advisory groups, which is the inventory of compliance the Chief AI Officer office must work against. GAO-25-107653 reported that across 11 selected agencies, total AI use cases nearly doubled from 571 in 2023 to 1,110 in 2024, with generative-AI use cases growing roughly nine-fold (32 to 282). That nine-fold gen-AI growth is the strongest single data point on the gen-AI inflection inside federal civilian work.

The talent constraint that ties it all together

The OPM CHCO memo "Building the AI Workforce of the Future" stated plainly that the federal government struggles to recruit and retain top STEM talent and that skills gaps in data science threaten to prevent the government from using AI to its full potential (OPM CHCO memo PDF). The U.S. Tech Force, OPM's response, will hire annual cohorts of 1,000 Fellows funded by the agencies they join (Federal News Network, December 2025). And OPM's December 17, 2025 CPM 2025-16 memo formally documented pay flexibilities for IT, cyber, AI, and other technical employees, putting AI talent on a pay band above standard GS scale (OPM CPM 2025-16 PDF).

Even with all of that motion, the binding constraint for most agencies and most states in 2026 is people, not policy. The Tech Force will deliver 1,000 Fellows a year against an addressable need of tens of thousands of agency AI roles. That gap is where vendor consulting, contractor staff augmentation, and managed services will fill in for the next 24 months.

What "AI ready" actually looks like for a public-sector mission

The vendor pitch deck version of AI readiness is a maturity model with five tiers and a slide of green checkmarks. The version that survives an IG review is shorter and harder.

A program area is AI-ready when its underlying data is documented (lineage, source system, refresh cadence), when its data quality is measured against a fixed threshold and meets it, when access controls are role-based and auditable, and when the people who run the program can describe the AI use case in one sentence with a measurable outcome and a stop-deployment criterion. If any of those four are missing, the program is not AI-ready and the vendor pitch is premature.

We saw the practical version of this at Texas Health and Human Services. HHSC was sizing a $12 million AI modernization decision and asked us to assess AI readiness across eight program areas. Three were ready for immediate AI deployment. Five required 6 to 18 months of data and process work first. The agency shifted $4.2 million from AI projects to foundational data work before deploying anything (Texas HHS AI Readiness Assessment, Thinklytics case study). That redirect, away from the AI line and toward the data line, is the most expensive move an agency can defer, and the most expensive mistake an agency can make.

The Florida Department of Education ran the same play on the data foundation side. Two prior internal attempts to unify student outcome reports from 67 districts had failed over two years. We unified all 67 districts on a single reporting platform in 14 weeks with zero change orders, automating $1.9 million in annual IPEDS reporting labor (Florida DOE Education Analytics, Thinklytics case study). The win was not the platform. The win was that, for the first time in six years, the Department had AI-ready data the moment it wanted to layer AI on top.

The City of San Antonio version of this story is data-quality remediation under a hard funding deadline. A federal audit found data-quality issues across 12 city departments that put $4.1 million in federal grant funding at risk. We delivered a 90-day remediation that preserved the funding and stood up nightly automated checks across all 12 departments (City of San Antonio Data Quality, Thinklytics case study). The lesson for AI: federal grant-recipient agencies that cannot pass an audit on the underlying data will not survive a Chief AI Officer's review of an AI use case built on that data.

The federal version is governance under FOIA pressure. A federal transportation agency was averaging 34 days for FOIA responses against a 20-day legal limit and absorbing $1.2 million per year in penalties. We deployed a centralized data catalog across six regional offices. FOIA response time fell to 8 days, the penalties stopped, and the catalog uncovered 18 TB of duplicate data (Federal Agency FOIA Data Governance, Thinklytics case study). Catalog-first is not just for AI. It is the precondition for it.

The Travis County Health Department version is the pattern that scales fastest at the local tier. Fourteen manual Excel reports replaced with Power BI dashboards in 12 weeks. Annual reporting labor down from $620K to $80K. Real-time disease surveillance that, three weeks after launch, identified a norovirus outbreak source four days faster than the prior weekly cycle could (Travis County Health Department Analytics, Thinklytics case study). Local agencies do not need an AI strategy to make AI possible. They need a data layer that an AI strategy can land on.

The 90-day plan that procurement, the CAIO, and the IG can all sign

The pattern that survives a federal IG review or a state-level open-records audit looks the same in every public-sector engagement we have run.

Days 1 to 30 are the inventory. The agency or state CIO office documents every active AI use case, every shadow GenAI deployment running on personal accounts, and every dataset that any of those use cases touches. The output is a single ledger that maps use case to dataset to risk tier to compliance owner. This is what the 2025 federal inventory exercise produced at scale, and it is what every state office should now mirror.

Days 31 to 60 are the readiness assessment on the top three use cases. For each, the team documents the data lineage, runs a quality check against a defined threshold, confirms access controls are role-based and auditable, and writes the one-sentence use-case statement with a measurable outcome and a stop-deployment criterion. Use cases that pass move to deployment scoping. Use cases that fail go to a remediation track with a named owner and a timeline.

Days 61 to 90 are the deployment of one use case end-to-end. One. Not three, not the full inventory. The first deployment establishes the procurement contract template under M-25-22, the CAIO sign-off process, the IG documentation package, and the post-deployment measurement plan. Every subsequent use case rides on that template at one-third the time and one-quarter the legal review.

Day 91 onward is replication. The agency or state office runs the same 30-day cycle on the next use case, then the next. Within 12 months a typical mid-tier state agency can move from inventory to 6 to 10 deployed AI use cases with full IG documentation. That cadence is faster than the agency-built version and produces a paper trail that survives political turnover.

What our federal, state, and local engagements have looked like in practice

We anchor public-sector AI work in the practices that the IG and the CAIO already know how to evaluate, and we let those practices carry the AI use cases on top.

Our AI Readiness work is the front end. It is what produced the $7.3 million automation map at Texas HHSC and the redirect of $4.2 million from AI projects to foundational data work. Our Data Foundation practice runs the platform consolidations like the Florida DOE 14-week unification of 67 districts. Our Data Governance Consulting practice runs the catalog and data-quality work like the City of San Antonio remediation and the federal transportation agency FOIA framework. Our Analytics & BI practice runs the dashboard consolidations like Travis County's 14 manual reports replaced. And our AI Workflow Automation Consulting practice deploys the AI use cases that ride on top of the data layer those programs built.

The shape of the engagement is the same across federal, state, and local. Inventory first. Readiness assessment on the top three use cases. One deployment end-to-end. Then replication. The variables are the regulatory regime (M-25-22 federal, TRAIGA in Texas, EO N-5-26 in California, NIST AI RMF as the floor everywhere) and the named oversight body (the agency IG, the state Auditor, the GAO portfolio).

Frequently asked questions

Does EO 14179 mean federal AI governance is gone?

No. EO 14179 rescinded EO 14110 but the underlying statutory and procurement requirements remain. M-25-22 explicitly preserves the procurement-disclosure and IP-rights provisions. NIST AI RMF and AI 600-1 are still the de-facto compliance reference. GAO inventories continue. The 94 government-wide AI requirements identified in GAO-25-107933 are still in force. What changed is the policy emphasis from precaution to acceleration. The compliance floor is still there.

Where should a state CIO office that's brand new to AI governance start?

Start with the inventory and the use-case ledger. NASCIO 2026 puts AI at #1, but most state CIO offices have no central record of where shadow GenAI is running on state data. The 30-day inventory exercise is the only thing that lets a CIO answer the State Auditor's first question.

Does TRAIGA apply to federal agencies operating in Texas?

TRAIGA's definition of "developer" and "deployer" is broad enough that federal contractors and grantees handling Texas-resident data should assume yes until counsel says otherwise. The NIST AI RMF affirmative defense provides a clean compliance path that works for both regimes simultaneously.

What does an IG actually look for in an AI use case review?

The four readiness criteria above (documented data lineage, measured data quality, role-based access controls, one-sentence use-case statement with measurable outcome and stop-deployment criterion) cover roughly 80 percent of what every IG and state Auditor we have worked with asks. The remaining 20 percent is regime-specific (M-25-22 disclosure, TRAIGA documentation, agency-specific records-management).

Should we wait for FedRAMP High to scope a GenAI pilot?

For workloads touching sensitive data, yes. Microsoft's December 2025 authorization across the full GenAI portfolio means the answer is "FedRAMP High is now available" for most major GenAI services. State and local equivalents are converging on StateRAMP. The 12-month wait that scoping conversations used to involve is largely closed.

Where are the 2026 procurement vehicles for AI services?

GSA OneGov is the front door for cloud and platform agreements (Adobe, Anthropic, AWS, Google, Microsoft, OpenAI). MAS Schedule for advisory and implementation services. State equivalents (Texas DIR, California CalNet, NASPO) for state-level work. The procurement vehicle question is now downstream of the use-case-readiness question, not the other way around.


If your agency, state office, or local jurisdiction is building its 2026 AI plan, the version of this work that includes the full source pack, the procurement timeline matrix, and the IG-defensible 90-day plan is available on request. We pair it with a no-obligation 30-day AI Readiness Assessment (details here) for one program area or one department.

The full Thinklytics public-sector practice pages are AI Readiness, Data Foundation, Data Governance Consulting, Analytics & BI, and AI Workflow Automation Consulting. The deepest case studies from this practice are Florida Department of Education, City of San Antonio, Texas Health and Human Services, a federal transportation agency, and Travis County Health Department.

Which states are leading on AI readiness?

California, New York, Texas, and Washington consistently rank highest in 2026 surveys. The leaders share three traits: an executive-level AI office, a published AI use-case inventory, and dedicated data-foundation funding. States missing any of the three trail by 18-24 months on average.

How does Thinklytics work with government agencies?

Through prime contractor partnerships on the data foundation work. Senior practitioners with experience at state and federal civilian agencies. We focus on the unified data layer; the prime handles change management. Read more at government industry.

Topics covered

  • government
  • ai-strategy
  • ai-readiness
  • data-governance
  • procurement

Frequently asked questions

Does EO 14179 mean federal AI governance is gone?

No. EO 14179 rescinded EO 14110 but the underlying statutory and procurement requirements remain. M-25-22 explicitly preserves the procurement-disclosure and IP-rights provisions. NIST AI RMF and AI 600-1 are still the de-facto compliance reference. GAO inventories continue. The 94 government-wide AI requirements identified in GAO-25-107933 are still in force. What changed is the policy emphasis from precaution to acceleration. The compliance floor is still there.

Where should a state CIO office that's brand new to AI governance start?

Start with the inventory and the use-case ledger. NASCIO 2026 puts AI at #1, but most state CIO offices have no central record of where shadow GenAI is running on state data. The 30-day inventory exercise is the only thing that lets a CIO answer the State Auditor's first question.

Does TRAIGA apply to federal agencies operating in Texas?

TRAIGA's definition of "developer" and "deployer" is broad enough that federal contractors and grantees handling Texas-resident data should assume yes until counsel says otherwise. The NIST AI RMF affirmative defense provides a clean compliance path that works for both regimes simultaneously.

What does an IG actually look for in an AI use case review?

The four readiness criteria above (documented data lineage, measured data quality, role-based access controls, one-sentence use-case statement with measurable outcome and stop-deployment criterion) cover roughly 80 percent of what every IG and state Auditor we have worked with asks. The remaining 20 percent is regime-specific (M-25-22 disclosure, TRAIGA documentation, agency-specific records-management).

Should we wait for FedRAMP High to scope a GenAI pilot?

For workloads touching sensitive data, yes. Microsoft's December 2025 authorization across the full GenAI portfolio means the answer is "FedRAMP High is now available" for most major GenAI services. State and local equivalents are converging on StateRAMP. The 12-month wait that scoping conversations used to involve is largely closed.

Where are the 2026 procurement vehicles for AI services?

GSA OneGov is the front door for cloud and platform agreements (Adobe, Anthropic, AWS, Google, Microsoft, OpenAI). MAS Schedule for advisory and implementation services. State equivalents (Texas DIR, California CalNet, NASPO) for state-level work. The procurement vehicle question is now downstream of the use-case-readiness question, not the other way around. --- If your agency, state office, or local jurisdiction is building its 2026 AI plan, the version of this work that includes the full source pack, the procurement timeline matrix, and the IG-defensible 90-day plan is available on request. We pair it with a no-obligation 30-day AI Readiness Assessment (details here) for one program area or one department. The full Thinklytics public-sector practice pages are AI Readiness, Data Foundation, Data Governance Consulting, Analytics & BI, and AI Workflow Automation Consulting. The deepest case studies from this practice are Florida Department of Education, City of San Antonio, Texas Health and Human Services, a federal transportation agency, and Travis County Health Department.

Which states are leading on AI readiness?

California, New York, Texas, and Washington consistently rank highest in 2026 surveys. The leaders share three traits: an executive-level AI office, a published AI use-case inventory, and dedicated data-foundation funding. States missing any of the three trail by 18-24 months on average.

How does Thinklytics work with government agencies?

Through prime contractor partnerships on the data foundation work. Senior practitioners with experience at state and federal civilian agencies. We focus on the unified data layer; the prime handles change management. Read more at [government industry](/industries/government).

Related reading

Thinklytics

Data and AI consulting for Fortune 500s, health systems, and growth-stage companies. Clean data, governed metrics, analytics ready for AI.

Austin, TX · United States

[email protected]