- The US federal government spends over $100 billion a year on IT, with about 80% going to keeping existing systems running rather than improving them (GAO, July 2025).
- GAO flagged 11 legacy systems across 10 agencies as most in need of modernization, some up to 60 years old, seven with known security weaknesses.
- Federal AI use is growing fast (3,600+ use cases reported in 2025, up 69% from 2024), but governance is lagging behind adoption.
- AI-enabled bolts AI onto an unchanged legacy system; AI-native redesigns the core workflow around AI from the start, which changes what compliance and governance work has to happen upfront.
- AI-native isn't always the right call: short-lived programs, low-volume workflows, and processes bound by deterministic decision rules are often better served staying AI-enabled or skipping AI altogether.
- A workable modernization roadmap treats planning, governance, and enterprise-wide coordination as prerequisites, not afterthoughts, based on where GAO and agency leaders say past efforts have failed.
What counts as government IT modernization right now?
Government IT modernization is the replacement or overhaul of the technology systems public agencies depend on to deliver services, the infrastructure, applications, and processes that sit behind everything from benefits processing to law enforcement records. It covers cloud migration, legacy application replacement, identity and data-sharing infrastructure, and, increasingly, where and how AI gets built into those systems.
The scale of the problem is well documented. The US Government Accountability Office (GAO), the audit arm of Congress, reported in July 2025 that US federal agencies spend over $100 billion annually on IT, with about 80% of that going toward operating and maintaining systems that already exist rather than building anything new.
GAO identified 11 legacy systems across 10 agencies as most in need of modernization, ranging from 23 to 60 years old, with three systems over 50 years old. Seven of the 11 carry documented security weaknesses, and only three had complete modernization plans in place. Eight still run on outdated languages like COBOL, which creates its own staffing problem as the developers who know these languages retire.
Why hasn't government IT modernization kept pace?
Two structural issues show up repeatedly in agency leaders' own accounts: agencies modernize in isolation, and modernization plans are often incomplete before work starts
Margie Graves, former Deputy Federal CIO, told the House Oversight Committee in April 2025 that "adoption rate for new technologies is slower than needed and transformations have not proceeded apace" (House Oversight Committee, April 2025). Suzette Kent, former Federal CIO, made a related point at the same hearing: clearing away legacy barriers in a systematic way is what brings modernization cost and complexity down, more than added funding on its own would.
The enterprise coordination gap
Maria Roat, former Deputy Federal CIO, has pointed to a pattern: agencies historically modernize independently of each other, which duplicates spending and misses savings that only show up when government is treated "as a single entity" rather than as separate departments. David Powner, former GAO Director of IT Issues, added a planning-discipline point in the same interview: agencies rarely track what legacy capability actually gets switched off once a new system goes live, which helps explain why old systems keep running years past their intended retirement. Powner was also direct about AI's limits here: "AI can help accelerate modernization, but it still requires human oversight, careful planning" to succeed.
That planning gap matches what GAO found directly: only 3 of the 11 highest-priority legacy systems had complete modernization plans, even though 7 of those 11 modernizations were already underway. Work was proceeding without the documentation GAO says is needed to avoid cost overruns and schedule delays.
The legislative response
Congress has taken notice. Rep. Nancy Mace introduced the bipartisan Modernizing Government Technology Reform Act (H.R. 2985) to increase transparency and modernize federal systems, adding to existing modernization vehicles like the Technology Modernization Fund and GSA's IT Modernization Centers of Excellence.
How fast is AI actually moving inside government?
Faster than most public discussion assumes, though adoption and governance are moving at different speeds.
Federal agencies reported more than 3,600 AI use cases in 2025, a 69% increase from 2024 and five times the 710 reported in 2023, according to a Brookings Institution analysis of federal use-case inventories, job postings, and agency interviews published in April 2026.
That growth is concentrated: five large agencies account for more than half of all reported use cases, and large agencies average 211 use cases each compared to 48 for midsize agencies and 5 for small ones. Mission-critical applications are already in production, including 52% of Social Security Administration use cases tied to benefits delivery and AI use in law enforcement records across the Department of Homeland Security and Department of Justice.
Gallup's Q4 2025 workplace survey found 43% of public-sector employees now use AI at least a few times a year, up from 28% in Q2 2024 and 17% in Q2 2023, with 21% using it daily or multiple times a week. The same survey found only 37% of public-sector employees say their organization has a clear AI strategy, compared with 53% in the private sector, and that frequent AI use jumps to 65% in agencies with strong managerial support versus 37% where support is weak. Strategy and support are the bottleneck, not access to the technology.
Governance is the part that's behind
A survey of more than 200 federal IT executives conducted by Market Connections in March 2026 found 53% of agencies are exploring or actively planning agentic AI pilots, with another 15% already implementing or having completed one. But the governance side hasn't caught up: only 20% of those agencies have defined pre-deployment testing policies, 8% have incident response frameworks, 6% have third-party vendor governance frameworks, and 29% have documented "kill switch" procedures for shutting an agentic system down. 77% of the executives surveyed said oversight frameworks are essential, and fewer than a third have actually implemented one.
This isn't unique to the US. The OECD's Digital Government Outlook 2026 found that AI is now used in at least one government function in 35 of the 36 OECD countries covered by the report (97%). The OECD has 38 member countries in total; the report's own figure is scoped to the 36 with 2025 data available, not to full OECD membership. Among those 36 countries, 86% use AI for internal processes (up from 70% in 2023) and 75% apply it to public services (up from 67% in 2023); 83% have set up dedicated institutions to govern AI use. Despite that, only 31% have formal algorithmic transparency standards and just 17% maintain a public registry of the algorithms government agencies actually use. The pattern across both US federal data and OECD-wide data is the same: adoption is outrunning governance.
AI-native vs. AI-enabled: What actually changes for a public-sector IT team
The distinction matters more here than in most industries, because public-sector systems carry legal accountability, public records, and citizen-facing consequences that a private-sector pilot doesn't.
An AI-enabled modernization keeps the existing legacy system as the foundation and adds AI as a feature layered on top, a chatbot in front of a benefits portal, a document-summarization tool bolted onto a case-management system. If the AI layer were removed, the underlying system would keep working exactly as it did before. An AI-native modernization designs the system's core workflow around AI from the outset, so removing the AI would mean the system no longer functions as intended (this "removal test" is explored in more depth in our companion pillar, AI-Native vs. AI-Enabled: How to Know When to Modernize Your Legacy Systems with AI.

For a public agency, that distinction changes what has to be in place before a project starts. An AI-enabled add-on can often go through an agency's existing security and compliance review because the underlying system of record hasn't changed. An AI-native rebuild touches the system of record itself, which means FedRAMP or StateRAMP authorization boundaries, records-retention rules, and audit trails all need to be designed in from the start rather than retrofitted. The governance gaps found in the Nextgov/FCW and OECD data above (thin incident-response plans, few vendor-governance frameworks, low rates of algorithmic transparency) are exactly the gaps that an AI-native project surfaces early and an AI-enabled add-on can more easily defer.
When should you not go AI-native?
Not every public-sector system is a good candidate. So in our opinion, three cases where staying AI-enabled, or skipping AI altogether, is the more defensible call are:
A system with a legislated sunset inside 24 months. If a program is scheduled for decommissioning or its statutory authorization expires within roughly two years, the fixed cost of an AI-native rebuild, including a new FedRAMP or StateRAMP authorization, won't pay back before the system is retired anyway. A lighter AI-enabled add-on, or no AI at all, is the more defensible use of that budget.
A workflow governed by a records-retention or explainability rule that non-deterministic output can't satisfy. Some benefits-determination, adjudicative, and law-enforcement record-keeping processes are bound by statutory or regulatory requirements for reproducible decision logic and a clean audit trail. Rebuilding that core workflow around a non-deterministic AI model complicates the legal defensibility those rules exist to protect. Keeping the deterministic decision engine as the system of record, with AI limited to an assistive layer on top, is the safer starting point.
A workflow with too little volume to justify the compliance overhead. FedRAMP and StateRAMP authorization is close to a fixed cost regardless of how many transactions a system handles. For a workflow that processes a small caseload, that authorization investment for a full AI-native rebuild often costs more than the process is worth. AI-enabled tooling layered onto the existing system is usually the more defensible call here.
What should a public-sector AI-native modernization roadmap include?
The following is Ayrin Digital's own recommended structure, built from where GAO and agency leaders say prior modernization efforts have specifically failed, not a single sourced framework.
- Start with a complete plan before writing code. GAO's finding that only 3 of 11 priority legacy systems had complete modernization plans is the clearest available evidence that this step gets skipped. A complete plan documents scope, milestones, a staffing plan, and a decommissioning plan for whatever the new system replaces.
- Design for cross-agency reuse, not single-agency deployment. Roat's enterprise-view critique applies directly to AI: an agentic workflow built for one agency's case-management system often generalizes to others. Evaluate shared-service potential (in the pattern GSA's own FedRAMP, Login.gov, and SAM.gov already use) before building a one-off.
- Build governance in from day one, not after a pilot succeeds. The Nextgov/FCW survey shows most agencies with agentic AI plans lack incident-response frameworks, vendor-governance frameworks, and kill-switch procedures. For an AI-native system, these aren't optional add-ons; they're part of the initial architecture.
- Track what gets decommissioned, not just what gets deployed. Powner's point about agencies failing to track what legacy capability actually gets retired is a fixable gap: a roadmap needs an explicit decommissioning milestone for every legacy system the new one replaces, with an owner and a date.
- Use existing federal modernization building blocks where they fit. GSA's own IT modernization guidance already covers cloud and data-center strategy, IPv6, low-code/no-code platforms, and Agile/DevSecOps delivery. An AI-native roadmap should build on these rather than replace them; AI-native refers to how the new system is designed, not a wholesale rejection of existing federal modernization practice.
Governance and oversight guardrails to build in from day one
Based on the OECD's three-pillar framework for trustworthy AI adoption (enablers, guardrails, and engagement) and the gaps the Nextgov/FCW survey identified, a public-sector AI-native project should have, before go-live: a pre-deployment testing policy, a documented incident-response plan, a vendor-governance framework covering any third-party AI component, and a kill-switch procedure with a named owner. Fewer than a third of federal agencies currently have all of these in place, which is precisely why they're worth calling out as a checklist rather than an assumption.

A practical starting point
Most agencies and the technology partners working with them don't need to solve every piece of this at once. The sequence that matches the evidence above: complete the modernization plan and decommissioning milestone first, evaluate whether the workflow could be a shared service before building it single-agency, then build governance and oversight into the initial architecture rather than adding it after a pilot proves the concept works. Skipping straight to a pilot without the first two steps is the pattern GAO's own data ties to cost overruns and stalled projects.



