Legacy Modernization

Government IT Modernization: An AI-Native Roadmap for the Public Sector

Government IT modernization means more than a cloud migration. See what makes a project AI-native, what's actually blocking progress, and a practical roadmap.

Key Takeaways
  • The US federal government spends over $100 billion a year on IT, with about 80% going to keeping existing systems running rather than improving them (GAO, July 2025).
  • GAO flagged 11 legacy systems across 10 agencies as most in need of modernization, some up to 60 years old, seven with known security weaknesses.
  • Federal AI use is growing fast (3,600+ use cases reported in 2025, up 69% from 2024), but governance is lagging behind adoption.
  • AI-enabled bolts AI onto an unchanged legacy system; AI-native redesigns the core workflow around AI from the start, which changes what compliance and governance work has to happen upfront.
  • AI-native isn't always the right call: short-lived programs, low-volume workflows, and processes bound by deterministic decision rules are often better served staying AI-enabled or skipping AI altogether.
  • A workable modernization roadmap treats planning, governance, and enterprise-wide coordination as prerequisites, not afterthoughts, based on where GAO and agency leaders say past efforts have failed.

What counts as government IT modernization right now?

Government IT modernization is the replacement or overhaul of the technology systems public agencies depend on to deliver services, the infrastructure, applications, and processes that sit behind everything from benefits processing to law enforcement records. It covers cloud migration, legacy application replacement, identity and data-sharing infrastructure, and, increasingly, where and how AI gets built into those systems.

The scale of the problem is well documented. The US Government Accountability Office (GAO), the audit arm of Congress, reported in July 2025 that US federal agencies spend over $100 billion annually on IT, with about 80% of that going toward operating and maintaining systems that already exist rather than building anything new.

GAO identified 11 legacy systems across 10 agencies as most in need of modernization, ranging from 23 to 60 years old, with three systems over 50 years old. Seven of the 11 carry documented security weaknesses, and only three had complete modernization plans in place. Eight still run on outdated languages like COBOL, which creates its own staffing problem as the developers who know these languages retire.

Why hasn't government IT modernization kept pace?

Two structural issues show up repeatedly in agency leaders' own accounts: agencies modernize in isolation, and modernization plans are often incomplete before work starts

Margie Graves, former Deputy Federal CIO, told the House Oversight Committee in April 2025 that "adoption rate for new technologies is slower than needed and transformations have not proceeded apace" (House Oversight Committee, April 2025). Suzette Kent, former Federal CIO, made a related point at the same hearing: clearing away legacy barriers in a systematic way is what brings modernization cost and complexity down, more than added funding on its own would.

The enterprise coordination gap

Maria Roat, former Deputy Federal CIO, has pointed to a pattern: agencies historically modernize independently of each other, which duplicates spending and misses savings that only show up when government is treated "as a single entity" rather than as separate departments. David Powner, former GAO Director of IT Issues, added a planning-discipline point in the same interview: agencies rarely track what legacy capability actually gets switched off once a new system goes live, which helps explain why old systems keep running years past their intended retirement. Powner was also direct about AI's limits here: "AI can help accelerate modernization, but it still requires human oversight, careful planning" to succeed.

That planning gap matches what GAO found directly: only 3 of the 11 highest-priority legacy systems had complete modernization plans, even though 7 of those 11 modernizations were already underway. Work was proceeding without the documentation GAO says is needed to avoid cost overruns and schedule delays.

The legislative response

Congress has taken notice. Rep. Nancy Mace introduced the bipartisan Modernizing Government Technology Reform Act (H.R. 2985) to increase transparency and modernize federal systems, adding to existing modernization vehicles like the Technology Modernization Fund and GSA's IT Modernization Centers of Excellence.

How fast is AI actually moving inside government?

Faster than most public discussion assumes, though adoption and governance are moving at different speeds.

Federal agencies reported more than 3,600 AI use cases in 2025, a 69% increase from 2024 and five times the 710 reported in 2023, according to a Brookings Institution analysis of federal use-case inventories, job postings, and agency interviews published in April 2026.

That growth is concentrated: five large agencies account for more than half of all reported use cases, and large agencies average 211 use cases each compared to 48 for midsize agencies and 5 for small ones. Mission-critical applications are already in production, including 52% of Social Security Administration use cases tied to benefits delivery and AI use in law enforcement records across the Department of Homeland Security and Department of Justice.

Gallup's Q4 2025 workplace survey found 43% of public-sector employees now use AI at least a few times a year, up from 28% in Q2 2024 and 17% in Q2 2023, with 21% using it daily or multiple times a week. The same survey found only 37% of public-sector employees say their organization has a clear AI strategy, compared with 53% in the private sector, and that frequent AI use jumps to 65% in agencies with strong managerial support versus 37% where support is weak. Strategy and support are the bottleneck, not access to the technology.

Governance is the part that's behind

A survey of more than 200 federal IT executives conducted by Market Connections in March 2026 found 53% of agencies are exploring or actively planning agentic AI pilots, with another 15% already implementing or having completed one. But the governance side hasn't caught up: only 20% of those agencies have defined pre-deployment testing policies, 8% have incident response frameworks, 6% have third-party vendor governance frameworks, and 29% have documented "kill switch" procedures for shutting an agentic system down. 77% of the executives surveyed said oversight frameworks are essential, and fewer than a third have actually implemented one.

This isn't unique to the US. The OECD's Digital Government Outlook 2026 found that AI is now used in at least one government function in 35 of the 36 OECD countries covered by the report (97%). The OECD has 38 member countries in total; the report's own figure is scoped to the 36 with 2025 data available, not to full OECD membership. Among those 36 countries, 86% use AI for internal processes (up from 70% in 2023) and 75% apply it to public services (up from 67% in 2023); 83% have set up dedicated institutions to govern AI use. Despite that, only 31% have formal algorithmic transparency standards and just 17% maintain a public registry of the algorithms government agencies actually use. The pattern across both US federal data and OECD-wide data is the same: adoption is outrunning governance.

AI-native vs. AI-enabled: What actually changes for a public-sector IT team

The distinction matters more here than in most industries, because public-sector systems carry legal accountability, public records, and citizen-facing consequences that a private-sector pilot doesn't.

An AI-enabled modernization keeps the existing legacy system as the foundation and adds AI as a feature layered on top, a chatbot in front of a benefits portal, a document-summarization tool bolted onto a case-management system. If the AI layer were removed, the underlying system would keep working exactly as it did before. An AI-native modernization designs the system's core workflow around AI from the outset, so removing the AI would mean the system no longer functions as intended (this "removal test" is explored in more depth in our companion pillar, AI-Native vs. AI-Enabled: How to Know When to Modernize Your Legacy Systems with AI.

Decision tree for government IT modernization: removing the AI component determines whether a system is AI-enabled (still functions) or AI-native (no longer works as intended).
AI-native vs. AI-enabled: The removal test for government systems

For a public agency, that distinction changes what has to be in place before a project starts. An AI-enabled add-on can often go through an agency's existing security and compliance review because the underlying system of record hasn't changed. An AI-native rebuild touches the system of record itself, which means FedRAMP or StateRAMP authorization boundaries, records-retention rules, and audit trails all need to be designed in from the start rather than retrofitted. The governance gaps found in the Nextgov/FCW and OECD data above (thin incident-response plans, few vendor-governance frameworks, low rates of algorithmic transparency) are exactly the gaps that an AI-native project surfaces early and an AI-enabled add-on can more easily defer.

Dimension AI-enabled AI-native
Starting point Existing legacy system stays the foundation System is redesigned around AI from the outset
If the AI layer is removed The underlying system keeps working as before The system no longer functions as intended
Compliance/ATO scope Often covered by the agency’s existing security and compliance review FedRAMP/StateRAMP authorization boundaries, records-retention rules, and audit trails must be designed in from the start
Governance readiness needed at launch Full AI governance (testing policy, incident response, vendor governance) can often be deferred, which is what most surveyed agencies currently do Governance gaps have to be resolved before go-live, since the AI layer is the system of record
Best fit Short-lived programs, low-volume workflows, or processes bound by deterministic decision rules High-volume, long-lived core workflows where the compliance investment pays back over time

When should you not go AI-native?

Not every public-sector system is a good candidate. So in our opinion, three cases where staying AI-enabled, or skipping AI altogether, is the more defensible call are:

A system with a legislated sunset inside 24 months. If a program is scheduled for decommissioning or its statutory authorization expires within roughly two years, the fixed cost of an AI-native rebuild, including a new FedRAMP or StateRAMP authorization, won't pay back before the system is retired anyway. A lighter AI-enabled add-on, or no AI at all, is the more defensible use of that budget.

A workflow governed by a records-retention or explainability rule that non-deterministic output can't satisfy. Some benefits-determination, adjudicative, and law-enforcement record-keeping processes are bound by statutory or regulatory requirements for reproducible decision logic and a clean audit trail. Rebuilding that core workflow around a non-deterministic AI model complicates the legal defensibility those rules exist to protect. Keeping the deterministic decision engine as the system of record, with AI limited to an assistive layer on top, is the safer starting point.

A workflow with too little volume to justify the compliance overhead. FedRAMP and StateRAMP authorization is close to a fixed cost regardless of how many transactions a system handles. For a workflow that processes a small caseload, that authorization investment for a full AI-native rebuild often costs more than the process is worth. AI-enabled tooling layered onto the existing system is usually the more defensible call here.

What should a public-sector AI-native modernization roadmap include?

The following is Ayrin Digital's own recommended structure, built from where GAO and agency leaders say prior modernization efforts have specifically failed, not a single sourced framework.

  1. Start with a complete plan before writing code. GAO's finding that only 3 of 11 priority legacy systems had complete modernization plans is the clearest available evidence that this step gets skipped. A complete plan documents scope, milestones, a staffing plan, and a decommissioning plan for whatever the new system replaces.
  2. Design for cross-agency reuse, not single-agency deployment. Roat's enterprise-view critique applies directly to AI: an agentic workflow built for one agency's case-management system often generalizes to others. Evaluate shared-service potential (in the pattern GSA's own FedRAMP, Login.gov, and SAM.gov already use) before building a one-off.
  3. Build governance in from day one, not after a pilot succeeds. The Nextgov/FCW survey shows most agencies with agentic AI plans lack incident-response frameworks, vendor-governance frameworks, and kill-switch procedures. For an AI-native system, these aren't optional add-ons; they're part of the initial architecture.
  4. Track what gets decommissioned, not just what gets deployed. Powner's point about agencies failing to track what legacy capability actually gets retired is a fixable gap: a roadmap needs an explicit decommissioning milestone for every legacy system the new one replaces, with an owner and a date.
  5. Use existing federal modernization building blocks where they fit. GSA's own IT modernization guidance already covers cloud and data-center strategy, IPv6, low-code/no-code platforms, and Agile/DevSecOps delivery. An AI-native roadmap should build on these rather than replace them; AI-native refers to how the new system is designed, not a wholesale rejection of existing federal modernization practice.

Governance and oversight guardrails to build in from day one

Based on the OECD's three-pillar framework for trustworthy AI adoption (enablers, guardrails, and engagement) and the gaps the Nextgov/FCW survey identified, a public-sector AI-native project should have, before go-live: a pre-deployment testing policy, a documented incident-response plan, a vendor-governance framework covering any third-party AI component, and a kill-switch procedure with a named owner. Fewer than a third of federal agencies currently have all of these in place, which is precisely why they're worth calling out as a checklist rather than an assumption.

Timeline showing a government AI-native modernization build track running parallel to the FedRAMP/StateRAMP authorization track, both converging at the ATO gate before go-live.
AI-native government modernization: Build and authorization tracks

A practical starting point

Most agencies and the technology partners working with them don't need to solve every piece of this at once. The sequence that matches the evidence above: complete the modernization plan and decommissioning milestone first, evaluate whether the workflow could be a shared service before building it single-agency, then build governance and oversight into the initial architecture rather than adding it after a pilot proves the concept works. Skipping straight to a pilot without the first two steps is the pattern GAO's own data ties to cost overruns and stalled projects.

Try Ayrin

We work through the AI-native vs. AI-enabled decision with teams directly

About the Author

Amropali has spent 14+ years building brands in the B2B space. Most recently she was Head of Global Marketing at Yellow.ai, where she rebuilt the brand and demand engine and grew inbound pipeline more than 4x. Before that, she founded and ran her own digital marketing agency serving clients in the US and India.

Amropali Shetty, Head of Marketing, Ayrin Digital

Amropali Shetty

Head of Marketing
Read more by this author

Not sure what your AI-native modernization roadmap should look like?

Ayrin Digital is an applied AI product and engineering firm. If your agency, or the systems integrator working with it, is scoping what an AI-native modernization roadmap should look like before committing a budget to a pilot, our team designs and builds AI-native systems and legacy modernization roadmaps from the ground up.

FAQ

What is government IT modernization?

Government IT modernization is the process of replacing or overhauling the technology systems public agencies use to deliver services, including legacy application replacement, cloud migration, and increasingly the design of AI-based systems, rather than continuing to patch and maintain decades-old infrastructure.

What's the difference between digital transformation and IT modernization in government?

IT modernization usually refers to replacing outdated systems and infrastructure. Digital transformation is the broader organizational shift, covering culture, processes, and service design, that IT modernization is meant to support. A modernized system without a matching process change rarely delivers the full benefit on its own.

Why do so many legacy government systems remain unmodernized?

GAO's own analysis points to two recurring causes: incomplete modernization plans (only 3 of 11 priority systems it reviewed had complete plans) and agencies modernizing independently rather than coordinating enterprise-wide, which duplicates cost and effort.

Is AI actually being used in government agencies today?

Yes, and the volume is growing quickly. Federal agencies reported over 3,600 AI use cases in 2025, up 69% from 2024, though nearly 60% of those use cases are still in pilot or pre-deployment phases rather than full production.

What's the difference between AI-enabled and AI-native government modernization?

An AI-enabled system adds an AI feature on top of an unchanged legacy system; removing the AI would leave the original system working as before. An AI-native system is designed around AI from the start, so removing it would mean the system no longer functions as intended. Public-sector systems carry compliance and records requirements that make this distinction matter more than in most industries.

What are the biggest risks of adding AI to legacy government systems?

The data points to a governance gap more than a technology gap: surveyed federal IT executives report low rates of incident-response planning, vendor-governance frameworks, and kill-switch procedures for agentic AI systems, even as adoption plans move ahead. Building those guardrails in from the start, rather than after a pilot, is the difference between an AI-native project and an AI-enabled one that inherits its predecessor's blind spots.