The Second Wave of State IT Consolidation: Authority, Identity, and AI
Back to Signal
State & LocalAIModernizationGovtechGovernmentInfrastructure

The Second Wave of State IT Consolidation: Authority, Identity, and AI

September 19, 2026Jess Loban

Infrastructure savings still matter

NASCIO's twentieth annual priorities survey includes 51 state and territory CIOs. AI reached number one for the first time, ending cybersecurity's twelve-year run at the top. Consolidation's return is significant, but the ranking does not establish that AI caused it or that cost reduction no longer matters. The priority description still includes services, operations, resources, infrastructure, and data centers.

Earlier consolidation programs offer useful context. Oklahoma's FY2019 executive budget reported completion of a six-year IT unification initiative involving 111 agencies, with estimated savings and cost avoidance exceeding $328 million. That is the state's historical estimate, combining two financial measures, rather than a recurring annual cash saving.

Reducing duplicate licenses, retiring underused servers, and coordinating patching remain worthwhile objectives. The next question is what authority accompanies the shared service. Moving an application into a common hosting environment does not automatically settle who approves its data access, defines acceptable model behavior, or resolves a dispute between program owners.

For an existing consolidated organization, that calls for a governance review. For a state considering reorganization, it calls for a business case that separates infrastructure savings from changes in decision authority.

Three decisions that deserve explicit owners

AI deployment. Identify who approves a use case, accepts its risks, controls access to sensitive data, and can suspend the service. Central IT can provide common evaluation tools and contracting terms while agencies retain responsibility for their program decisions. A federation needs binding responsibilities, an exception process, and a way to resolve disagreements; an organization chart alone provides none of those operating details.

Identity and access. Zero trust does not require every agency to use one identity product. NIST's Zero Trust Architecture focuses on protecting resources and making authentication and authorization decisions without granting trust merely because of network location or ownership. A state can apply those principles with federated identities if it establishes trustworthy assertions, appropriate access policies, and effective revocation.

Test cross-agency access: whose credentials are accepted, which device conditions matter, how permissions expire, and who investigates an anomalous session. Multiple identity platforms do not by themselves prove an open lateral-movement path. Excessive permissions, weak trust relationships, missing enforcement, or poor visibility are the conditions a security assessment needs to find.

Data meaning and quality. Cross-agency AI can combine records that use different definitions, dates, identifiers, and collection practices. Before pooling those records, assign owners for definitions, lineage, permissible uses, and corrections. Common standards should preserve necessary program distinctions rather than force unlike records into an apparently uniform dataset.

Tools can detect some inconsistencies. They cannot decide whether two agencies have the same legal authority to use a record or whether two similarly named fields represent the same event. Those decisions need the people responsible for the data and the public service.

Connect security operations to the service being protected

AI adds concrete monitoring questions: can an untrusted input influence an agent's tool use, can an account access data outside its task, and can an unauthorized change enter the model or data pipeline? Shared security operations can help correlate events across agency services, provided the relevant telemetry, access permissions, and response responsibilities are in place.

Centralization is not a substitute for that coverage. A single SOC with incomplete application logs can miss an AI-specific incident; an integrated federation can coordinate a response if its members exchange useful evidence and know who can act.

A cross-agency exercise should follow one representative incident from detection to containment. Include the application owner, identity team, data steward, service operator, and agency leadership. Measure where evidence or authority is missing before choosing a larger organizational remedy.

Idaho shows the range of work involved

Idaho's FY2026–2029 ITS strategic plan places consolidation alongside cybersecurity, communications, cloud strategy, AI policy, and enterprise data goals. Its performance measures list Idaho State Police and Juvenile Corrections for FY2026 with 22 FTE and 12,170 customers supported. The plan emphasizes retaining and reassigning existing agency IT staff; the figure should not be read as 22 newly created positions.

The document identifies legislative support, staff capacity, and budget availability as dependencies. A strategic plan establishes direction and measures; it does not itself demonstrate an appropriation or prove every phase is complete.

Its broader lesson is to plan several capabilities together. Policy, technical services, workforce transfer, and agency communication all appear in the same program. That supports coordinated planning without assuming every state must finish consolidation before beginning AI or zero trust work.

Authority works better when the service earns trust

The NASCIO and Forrester investment-management report draws on CIO survey data and interviews with 19 CIOs. It emphasizes agency trust, mission outcomes, and sustainable funding across different organizational models. One example describes consolidation of more than 20 identity systems after a CIO presented the expected operational benefits and built agency support, followed by political pressure to secure full participation.

That sequence is useful: explain what improves, hear the agency's constraints, and establish service commitments before exercising authority. A highly capable agency may have legitimate concerns about moving into a shared service with slower response times or less specialized support. Addressing those concerns strengthens the consolidation case.

Funding deserves the same precision. Agencies need to understand what an internal charge covers, including security, resilience, integration, and staffing. A chargeback model should be tested against realistic adoption and demand. Replacing it with direct appropriations still leaves a prioritization problem when more agencies request work than the shared team can deliver.

A practical decision checklist

Before approving a consolidation phase, require a brief answer to each question:

  1. Which mission is blocked? Name the application, agencies, dependency, and measurable consequence. Avoid using AI readiness as a substitute for a specific problem.
  2. What authority changes? Identify who will set standards, approve exceptions, fund remediation, and accept operational risk.
  3. What stays with the agency? Preserve program expertise, statutory responsibilities, and a clear route to influence service priorities.
  4. What does the service promise? Establish support levels, recovery expectations, escalation paths, and evidence that the provider can meet them.
  5. How does the budget work? Separate transition costs, continuing operations, cash savings, and avoided future spending. Test lower adoption and higher support demand.
  6. How will progress be measured? Track service reliability, access-control coverage, data defects, time to resolve issues, and public-service outcomes alongside the number of migrated systems.

A phased approach lets leaders validate those assumptions before expanding scope. The objective is a state technology organization that can make shared decisions, deliver reliable services, and sustain agency confidence as new capabilities arrive.

Sources and further reading

Spartan X brings AI, cybersecurity, and engineering expertise to the decisions that connect governance with working services: accountable access, usable data, reliable operations, and a transition plan agencies can execute.

Share this article
LinkedIn

BUILD WITH US

Ready to Solve Hard Problems?

Spartan X builds AI systems, autonomous platforms, and cybersecurity solutions for defense and national security.