Skip to main content
blogstateaipart2

Readiness Is the Foundation: How States Are Building AI Governance, Capacity, and Infrastructure

The first version of the report in 2025 solely focused on readiness metrics. While the evaluation expanded this year, AI Readiness capabilities are the fundamental building blocks for the AI journey.   The report describes Stage 1 as the “institutional awakening” to AI. It is the point where states move from observing AI as an external trend to treating it as a governance responsibility. Many more states took up this mantle in the last year.  

The Three Foundations of Responsible Government AI

Before AI can be used to improve public services, government needs the right foundations. That is the central message of the Readiness stage in Code for America’s Government AI Landscape Assessment. The report defines readiness as the institutional foundation that must exist before AI can be used responsibly at scale. It focuses on three pillars: leadership, capacity building, and infrastructure.

These pillars may sound administrative, but they are deeply practical. Without leadership, no one is accountable for creating the context and cultural change necessary for AI adoption. Without capacity building, employees do not know how to use AI well. Without technical and data infrastructure, promising pilots cannot scale.

1. Leadership: Who is accountable?

AI adoption in government cannot be left to scattered experimentation alone. Someone needs to own the strategy, set guardrails, coordinate across agencies, and make decisions about risk. The report emphasizes that most states now sit in the Developing or Established range for leadership and governance

The report finds that states with strong executive leadership and dedicated AI governance bodies move faster. AI responsibilities are increasingly assigned to CIOs, chief data officers, senior advisors, or working groups.  AI governance is often layered onto existing technology roles, while ome state have instituted a standalone Chief AI Officer. The underlying research notes that there is disagreement about whether a Chief AI Officer role is necessary. Some states create a dedicated role; others assign AI responsibility to a Chief Information Officer, Chief Data Officer, or cross-agency governance body.  A dedicated AI executive is not the only valid model. What matters is whether the state has clear ownership, risk review, cross-agency coordination, and the ability to move from guidance to enforceable governance for AI adoption and use.

Examples from the public report show different approaches. Georgia has a chief data and AI officer within the Georgia Technology Authority and has invested in an AI Innovation Lab and controlled sandbox environment. New York has a chief AI officer and the Empire AI initiative, which includes workforce upskilling and a sandbox environment for safe employee experimentation.

The report also notes the roles that legislatures and governors can play vital roles in setting the context for responsible AI with goals, guiderails, and industry partnerships to accelerate AI adoption.  On the legislative side, many states have seen committees take up discussions and increasing amounts of legislation. On the executive side, many governors have issues executive orders to spell out goals and guardrails, have created inter-agency learning efforts, and assigned administrative leadership responsbility. 

The lesson is straightforward: states move faster when AI leadership is visible, empowered, and connected to agency operations.

2. Capacity Building: Can public employees use AI well and responsibly?

Government AI adoption depends on the people who work in state government. Public employees need to understand what AI can do, where it can fail, when human review is required, and how to protect sensitive information. Training is not an optional add-on. It is a core readiness requirement.

The report identifies workforce readiness as a major driver of adoption and notes that training public employees in AI tools is essential. To meet those needs, some states have established their own training programs (including some who have implemented mandatory trainings on responsible AI use). Other states have established partnerships with training organizations such as InnovateUS or their universities systems.

The 2025 research found that capacity building was one of the least mature areas across states. Many states were still in early stages, with only a smaller group offering structured AI training or workforce development at scale. That gap matters. Without training, AI use may become either too cautious or too risky. Some employees may avoid useful tools entirely. Others may use public AI systems without understanding privacy, accuracy, bias, or security concerns.

This year's analysis saw significant gains in capacity building and further articualtion of what good training should include:

  • AI literacy for all employees

  • Role-specific training for program, policy, legal, technology, and frontline staff

  • Guidance on responsible generative AI use

  • Training on human oversight and verification

  • Communities of practice across agencies

States that invest in capacity are not just teaching employees how to use tools. They are building the human judgment needed to use AI in public-serving environments.

3. Infrastructure: Can AI scale safely?

AI depends on data, computing resources, system integration, and secure technical environments. Without modern infrastructure, states may be able to run pilots but struggle to move them into production. The report’s readiness framework identifies infrastructure as the technical foundation for AI, including data accessibility, computing resources, platforms, and vendor partnerships. It also highlights a key trend: states with enterprise data platforms tend to progress more quickly toward operational AI.

This is especially important in benefits delivery and public services. AI systems often require access to reliable, well-governed data across agencies. If data is siloed, incomplete, inconsistent, or difficult to access, AI tools may reproduce those weaknesses at scale.

Strong infrastructure does not mean rushing to automate decisions. It means building the technical conditions for safe experimentation, rigorous evaluation, and responsible implementation.

That includes:

  • Data governance

  • Secure cloud or hybrid environments

  • Interoperable systems

  • AI sandboxes

  • Procurement standards

  • Vendor oversight

  • Cybersecurity protocols

  • Model monitoring capabilities

Infrastructure is often invisible to residents. But it determines whether AI can actually improve government services—or simply add another layer of complexity to already strained systems.

Readiness is not the end goal

Readiness is only the first stage. But it determines the quality of everything that follows.

A state with weak governance may launch pilots without accountability.
A state with weak capacity may put tools in employees’ hands without enough guidance.
A state with weak infrastructure may generate promising demos that never scale.

The public report makes clear that readiness is where states ask the foundational questions: who is accountable, how AI should be governed, and what capabilities must exist to guide responsible use.

What the 2026 evaluations show

The full report’s readiness comparison shows meaningful movement between 2025 and 2026. Several states moved up one tier in overall readiness, including Colorado, Delaware, Georgia, Iowa, Kentucky, Louisiana, Maryland, Michigan, Minnesota, Missouri, Montana, New York, North Carolina, Oregon, South Dakota, Texas, and Washington. No state moved backward in the readiness comparison.

That matters because readiness is correlated with later-stage performance. The report notes that stronger foundational readiness is strongly associated with stronger piloting performance and remains moderately associated with stronger implementation and impact performance. Infrastructure is especially predictive of later-stage performance, particularly impact measurement and learning.

Case study: Georgia’s AI Innovation Lab

Georgia is one of the clearest examples of a state turning readiness into practical capacity.

The public report highlights Georgia’s chief data and AI officer within the Georgia Technology Authority and the state’s investment in both a digital and physical AI Innovation Lab. That lab functions as a controlled sandbox where pre-vetted vendors can work directly with state agencies to develop AI pilot projects.

This matters because Georgia’s readiness is not just a policy statement. It is a governance-and-infrastructure model: leadership, vendor controls, sandboxing, and agency engagement are connected.

Case study: New York’s executive leadership and sandbox infrastructure

New York is another state-level example of readiness translating into an institutional model. The public report notes that New York has a chief AI officer and launched the Empire AI initiative, which focuses on employee upskilling and infrastructure for AI testing and deployment. It also includes a proprietary generative AI sandbox environment built by the Office of Information Technology Services, allowing employees to practice using AI on work tasks with state-provided safe data.

New York’s model shows how readiness can combine leadership, training, technical safeguards, and learning infrastructure. This is important because AI readiness is not just about authorizing use. It is about creating safe conditions for learning.

Case study: Colorado’s readiness leap

Colorado moved from Established in the 2025 readiness baseline to Advanced in the 2026 update.

This reflects a broader pattern: states that combine policy, task forces, agency guidance, and data governance tend to move faster. Colorado’s broader AI posture includes legislation, governance structures, and attention to responsible deployment. The public report also notes that formal pilot case studies from Colorado are among the strongest Stage 2 evidence nationally.

Takeaway

Readiness is not the flashy part of AI adoption, but it is the foundation that determines whether everything else works. States that build clear governance, workforce capacity, and modern infrastructure are better positioned to pilot responsibly, implement reliably, and eventually measure public value. Responsible AI starts before any model is deployed. It starts with leadership, workforce capacity, and infrastructure. States that invest in these foundations will be better positioned to move from experimentation to meaningful public impact.

Next in the series: How states are using pilots, sandboxes, and AI labs to learn before they scale.

Check out the full report on Code for America's site.

Add new comment

Restricted HTML

  • You can align images (data-align="center"), but also videos, blockquotes, and so on.
  • You can caption images (data-caption="Text"), but also videos, blockquotes, and so on.
At HumanServices.ai, we are dedicated to revolutionizing the way human services are delivered. Our cutting-edge approaches to AI technology and innovation empower communities, streamline processes, and ensure that every individual receives the support they need.

Contact info

Recent Posts