Sunday, 30 August 2026 PDT | 12:11 PM
The 1 News Alt Logo Text Smart News for Global Indians

50 States, 50 Different Ways: Who Owns AI Once It's Deployed?

AI News August 06, 2026 05:30 AM
50 States, 50 Different Ways: Who Owns AI Once It's Deployed?

States have spent the last few years building the rules of the AI road.They have drawn lanes, installed guardrails and mapped where the technology should enter government. Executive orders were signed. Advisory councils formed. Responsible AI policies published. And in many states, chief AI officers were named. But building figurative road maps was the easy part. Now, as AI moves from pilot projects into the daily machinery of government, states are facing a new question: who takes the wheel after AI has gone live?The answer, in most states, is not a single executive or even a specific office. In fact, AI governance has started to become less of one person's responsibility and more of a relay race, wherein central technology teams set rules before passing the baton to other agencies after systems go live. But how that handoff works currently varies by state.

“It’s not the same across the board,” said Meredith Ward, deputy executive director of the National Association of State Chief Information Officers (NASCIO). “If you’ve seen one state, then you’ve seen one state, meaning 50 states could have 50 different ways of doing things.”To get a sense of whether any patterns are emerging, Government Technology recently spoke with officials in three states, as well as a pair of experts, all of whom discussed the evolving approach to AI governance in the public sector.Who Sets the Initial Rules?

States have increasingly centralized AI governance, but centralization does not mean that a single office controls every decision.In many states, CIO offices or emerging technology teams have become responsible for creating frameworks by developing policies, reviewing use cases, maintaining inventories and ensuring agencies understand the risks before deploying AI. The goal is less about finding one person to control AI. It's closer to finding someone to make sure everyone follows the same rules.Maryland is one state working to thread that needle — a narrow space between centralized oversight and agency autonomy, where states are trying to prevent AI from becoming either a free-for-all or a bureaucratic bottleneck.Michael Boyce, the state’s AI adviser, said the Maryland Department of Information Technology establishes guardrails for AI use, including security, privacy and data standards. Agencies must complete the department’s AI intake process before deployment to verify that proposed use cases meet those requirements.But once an AI system is approved, ownership moves back to the individual agency itself. Essentially, day-to-day accountability for a deployed AI system rests with the agency that owns the approved use case.California, meanwhile, is navigating a similar balancing act. Monica Hernández, deputy director of communications and stakeholder relations for the California Department of Technology, described her state’s AI governance as a shared responsibility that goes much further than deployment. She said the California Department of Technology establishes statewide policy, governance requirements and oversight. Agencies, meanwhile, remain responsible for operation, monitoring, risk management, compliance and managing the systems that they use every day.But the handoff between central oversight and agency ownership looks slightly different in a state like Pennsylvania, where the IT agency has focused on adding more voices before AI moves from idea to implementation.Daniel Egan, director of communications for the state’s Office of Administration, said generative AI deployments in Pennsylvania undergo a multidisciplinary review process led by the Emerging Technology Office within the Commonwealth Office of Digital Experience, with input from the Generative AI Governing Board, privacy and security officers, and legal counsel.At the same time, Egan said the agency or program implementing the use case also shares responsibility for the deployment.Ownership After LaunchBuilding an approval process is relatively straightforward compared with pinpointing what happens after an AI system goes live.If an AI tool produces inaccurate recommendations, introduces bias or creates unexpected outcomes, states generally do not expect a central AI office to step in and manage each issue. Instead, agencies using the technology are expected to monitor performance, understand limitations and address problems.In Maryland, Boyce said it does fall on individual agencies to manage AI issues in the first instance. That includes monitoring performance, auditing outputs for accuracy and bias, maintaining error logs, and following incident response procedures. Security or privacy incidents, however, move through the state’s Security Operations Center.California operates similarly. The state’s central technology office provides governance and oversight, but agencies remain responsible for managing deployed systems and making sure they continue meeting operational and compliance requirements.But some experts say the road gets bumpier when responsibility is shared without a clear destination or a clear driver.Andrew Merluzzi, AI Innovation and Incubation Fellow at the Beeck Center, said that while many states have made strides creating governance structures, operational accountability has not always evolved at the same pace. Basically, states have made great progress on central governance, while AI at the operational level remains more fragmented.Merluzzi said that big moves such as executive orders, task force launches or statewide AI inventories do not automatically answer questions about who handles errors when they occur. That’s much more of an operational question, and for many states, the answer is still shaking out.This leads to one oft-overlooked puzzle piece: governance can define rules, but it cannot take responsibility. People have to do that.Merluzzi said every deployed AI system should have a specific person named and responsible for the use cases.Without that, governments risk what Merluzzi called a diffusion of responsibility, where multiple offices may be involved but no single person is accountable for performance, monitoring or improvement.As such, the best models at the state levels have both a set of central standards, as well as a lot of operational decision-making lower down in the agencies or even on individual teams.Chief AI officers, Merluzzi said, are also not necessarily meant to become the sole authority over AI. Instead, their role is to translate broad principles into repeatable practices. This includes creating risk tiers, developing evaluation standards, establishing escalation procedures and more.All this occurs while CIOs continue to focus on enterprise technology decisions, including tools, contracts and technical controls.AI Will Show Up AnywayBut potentially one of the biggest challenges states face is that AI does not always arrive wearing an AI label. Increasingly, AI capabilities are being built into software that governments already use, even if they don’t realize it. A productivity platform update, a customer service application or an enterprise system upgrade can introduce new AI functionality without an agency intentionally purchasing a separate AI product.From NASCIO’s perspective, Ward identified embedded AI capabilities as one of the biggest governance challenges facing states because software updates can introduce new AI features, expanding the potential attack surface while reducing visibility into where AI is entering government environments.The shift hasn’t been lost on cybersecurity leaders. According to the 2026 NASCIO-Deloitte Cybersecurity Study, 94 percent of state CISOs reported actively participating in developing generative AI security policies, while 84 percent are involved in strategy development and use case reviews.One state CISO featured in the report framed the concern this way:“GenAI is advancing faster than existing governance structures can adapt, creating growing uncertainty around security, privacy and ethical use. Vendors are increasingly embedding AI capabilities into products and services without sufficient transparency or state-level control, effectively inflicting AI on operational environments before comprehensive risk assessments or policy frameworks can be applied.”This has, in turn, pushed states to make procurement somewhat of a checkpoint.Pennsylvania requires enterprise security and emerging technology reviews whenever AI is purchased, either as a standalone application or as part of another technology product.California’s governance framework expects agencies to evaluate embedded AI features during procurement and implementation.Maryland routes AI capabilities through its intake process before agencies deploy them, including AI features built into existing enterprise software.The bottom line is that embedded AI capabilities should require the same scrutiny as any other AI deployment.But even the most carefully designed governance framework can run into a human variable. Employees still need tools that work for the way they actually do their jobs.Ward noted that AI accountability ultimately resides with the agencies and employees utilizing these solutions. That is where states are confronting a familiar technology problem. When approved tools are difficult to access, employees often find alternatives on their own.Ward said acceptable use policies have become one tool states use to manage what many call shadow AI, but policies alone cannot solve the human side of adoption.Merluzzi shared the same philosophy, noting that restrictions alone are unlikely to solve the problem. Employees often turn to unauthorized AI tools when the tool they need has not yet been approved, because approval processes take too long or because employees do not know which tools they are permitted to use.Essentially, simply banning AI doesn’t eliminate use, but it does often drive it underground.The Next Challenge: Measuring SuccessFor all of these remaining challenges and questions, NASCIO’s forthcoming 2026 State CIO Survey notes that state AI governance has matured relatively quickly.According to data that Ward shared from the report, 98 percent of states have implemented enterprise policies governing generative AI development and use — up from 76 percent in 2025. And 84 percent of states have established AI advisory committees or task forces, up from 82 percent in 2025, while more than 44 states now have an AI officer, director or equivalent role, primarily housed in CIO offices.States have quickly moved beyond early conversations about whether AI needs governance, with Ward noting that AI governance is now essentially operational in all states.Merluzzi, for his part, said that the next phase of AI governance may require states to answer tougher questions. Who owns each system? Who monitors performance? What happens when results decline? When should an AI tool expand, change or be retired?Those answers will determine whether AI governance becomes more than a collection of policies and approval forms. Because in the end, the hardest part of governing AI may not be deciding what technology governments can and should start using, but who is responsible for it after they put AI to use.

Ashley Silver is a staff writer for Government Technology. She holds an undergraduate degree in journalism from the University of Montevallo and a graduate degree in public relations from Kent State University. Silver is also a published author with a wide range of experience in editing, communications and public relations.