A state CIO does not ask whether AI works. Most of them have already seen it work in a pilot. The question a state, county, school district, or agency leader asks is whether the procurement vehicle, the budget cycle, and the compliance chain can absorb a tool that changes every few months when the appropriations process moves once a year. That mismatch, not skepticism about the technology, is the real story in public sector AI adoption right now.
This article is grounded in current advisory work, not retrospective analysis. Mark Lynd is a 5x CEO/CIO/CISO with Thinkers360 Top 10 global rankings across Cybersecurity and Artificial Intelligence and was ranked #1 globally in Cybersecurity in 2023. He is currently Head of Executive Advisory and Strategy at Netsync, advising enterprise C-Suites and boards on the AI and cybersecurity questions moving fastest in 2026. The frameworks and patterns referenced here are from active engagements this quarter.
Adoption Is Real, and Growing Faster Than the Private Sector Assumes
Gallup's public sector workforce data shows AI use among government employees climbed from 17 percent using it frequently in the second quarter of 2023 to 43 percent using it at least a few times a year by the fourth quarter of 2025, with 21 percent now using it daily or multiple times a week. That is not a slow moving sector. Gallup's same data shows private sector frequent use at 25 percent against the public sector's 21 percent, a real but narrow gap, while public sector occasional use actually leads private sector by six points. The narrative that government is years behind commercial adoption does not match the survey data anymore.
What does separate public sector adoption is what happens after an employee starts using a tool informally and an agency tries to procure and govern it formally. NASCIO's 2025 State CIO Survey, now in its twentieth year of ranking state technology priorities, put artificial intelligence at the top of the list for the first time, ahead of cybersecurity and budget management, with emphasis specifically on governance, security and privacy, workforce skills, data quality, and ethical use. Budget and cost control ranked third, cited by state CIOs as a persistent constraint on funding new technology categories including AI. Those two priorities sitting at numbers one and three describe the actual tension SLED leaders manage daily. They want AI. They do not have a budget cycle built for it.
The Constraints That Do Not Exist in Commercial Procurement
A commercial enterprise CIO can often approve a departmental AI pilot from an existing software budget line and expand it within a quarter if it works. A state agency or school district usually cannot. Procurement in SLED environments runs through competitive bid requirements, sole source justification thresholds, and appropriations cycles set a year or more in advance. An AI capability that a vendor updates monthly has to be evaluated, justified, and funded against a budget document written before that capability existed in its current form.
Compliance adds a second layer that commercial buyers rarely face in the same way. Federal agencies lean on FedRAMP authorization to establish a baseline of vetted cloud security controls before a tool can touch federal data. States and localities increasingly use StateRAMP, a parallel framework built specifically because FedRAMP was designed for federal use and left a gap for state and local government buyers who needed an equivalent security baseline without duplicating the federal authorization process from scratch. A vendor without StateRAMP or an equivalent authorization is, in many states, simply not eligible for agencies handling sensitive data, regardless of how good the product is. That authorization gap alone screens out a meaningful share of commercial AI vendors who built their compliance posture around SOC 2 and assumed it would transfer.
Workforce readiness is the third constraint, and it compounds the first two. NASCIO's governance priority explicitly names workforce skills alongside security and data quality, because a tool that clears procurement and compliance still needs staff who can operate it inside public sector constraints, including public records law, accessibility requirements, and constituent facing accountability that a commercial deployment does not carry in the same form.
None of these three constraints are new to public sector technology buyers. Cloud migration and cybersecurity modernization ran into the same procurement friction a decade ago. What is different with AI is the pace mismatch. A cloud vendor's product roadmap moved in years, which a multi year appropriations cycle could reasonably track. An AI vendor's underlying model can change materially in a single quarter, and a SLED procurement process built around annual or biennial budget cycles has no mechanism to reauthorize that fast, even when the agency wants to.
A Worked Example
A mid sized county government wanted to deploy an AI tool to help caseworkers draft benefits eligibility summaries faster. The tool itself was proven, the vendor had commercial references, and caseworkers in a limited pilot reported real time savings. The rollout stalled for eleven months, not because the technology failed, but because of three separate constraints stacking on top of each other. The vendor lacked StateRAMP authorization, which triggered a sole source security exception process that took four months. The county's procurement code required a competitive bid above a certain dollar threshold, which the AI tool's multi year contract value crossed, adding a formal RFP cycle. And the county's records retention policy had no defined category for AI generated draft text, which meant legal counsel had to resolve a public records question before caseworkers could use the tool on live cases. None of those three issues would have appeared in a commercial enterprise deployment of the same tool. All three were foreseeable, and all three were avoidable with earlier engagement between IT, procurement, and legal instead of sequential handoffs.
The Honest Counterargument
The strongest case against slow, compliance heavy SLED AI adoption is that public services suffer while the process runs. A caseworker still processing benefits applications by hand for eleven months while a proven tool sits unauthorized is a real cost, borne by residents waiting on services, not an abstract governance concern. Critics of SLED procurement speed have a fair point when the delay is bureaucratic inertia rather than genuine risk management, and plenty of public sector delay is exactly that, process for its own sake rather than a response to a real threat.
But the counterargument weakens when the data involved is protected, whether that is benefits eligibility records, student data under FERPA, or law enforcement information. The same speed that serves residents well in a low risk pilot creates real exposure in a high risk one, and the agencies that skip authorization steps to move faster are the ones that end up in a breach disclosure instead of a case study. The right response is not slower process across the board. It is a tiered approach, fast tracking low risk AI tools while holding the full compliance chain for anything touching regulated data, which is closer to what StateRAMP itself was built to enable.
Monday Questions for Leadership and the Board
Ask procurement leadership which AI vendors currently under evaluation have StateRAMP or FedRAMP authorization, and which do not. Ask IT how many active AI pilots would survive a formal RFP cycle if scaled past pilot status, and what that timeline actually looks like. Ask legal and records management whether a policy exists yet for AI generated content under public records law. Ask HR and workforce development what training exists for staff operating AI tools inside public accountability requirements. These questions are not about slowing adoption. They are about surfacing the eleven month stall before it happens instead of after.
Public sector leaders are not behind on AI. They are ahead of a procurement system that was never built for a technology that changes faster than an appropriations cycle.