States want ‘digital front doors,” but funding and AI-powered fraud are interfering
While most states work to build a “digital front door” that improves resident login and identity systems for government services, state leaders said challenges like funding and artificial intelligence-based fraud are getting in the way, according to a report published this week.
The report, published Tuesday by the National Association of State Chief Information Officers and based on NASCIO President and Arizona CIO J.R. Sloan’s 2026 presidential initiative, found that while many states are working to create digital front doors by moving away from fragmented login and identity systems toward centralized or hybrid enterprise approaches, significant hurdles remain for both states and residents.
While those challenges often motivate governments to build a statewide digital identity infrastructure in the first place, state leaders said turning those efforts into a workable statewide system requires enterprise governance, sustained funding, executive sponsorship and agency buy-in.
The findings were based on survey responses from CIOs, chief information security officers and chief technology officers across 47 states, 51% of which said their state was working toward this centralized approach to citizen digital identity.
Such systems would allow residents to create one trusted identity or account that is accepted by multiple state agencies and services, rather than requiring them to create and manage separate accounts. States say that when identity management is siloed, residents often have to maintain multiple login credentials and identity records across agencies, which can be confusing for residents, create duplicative administrative work for agencies, and present risks like inconsistent security controls and difficulty maintaining identity systems on legacy technology.
Another motivation for consolidated systems, state leaders said, was making government services feel more like modern consumer digital services — one account, fewer logins and less repeated identity verification.
Security and fraud are other major drivers. While the COVID-19 pandemic exposed weaknesses in fragmented identity systems, states are becoming increasingly concerned about fraud targeting benefits and other citizen-facing services that use AI. The technology has made it much easier for bad actors to deploy synthetic identities, deepfakes, AI-generated impersonation, automated account abuse and increasingly sophisticated phishing schemes to abuse government services and benefits.
Preparedness for these more sophisticated threats to identity also varies dramatically across the states. Some have sophisticated, layered systems, while others are still figuring out how AI changes their cyber threat models. And some don’t yet have formal AI-specific identity threat playbooks or governance structures, the report found.
Despite these newer threats, identity management has been an ongoing focus for state tech leaders — it’s been featured in the NASCIO State CIO Top Ten Technology list annually except for 2015, and appears on the organization’s Top Ten Strategies list every year starting in 2021. But implementation has been far less consistent: According to the 2024 State CIO Survey, only 13% of state CIOs said they had a fully implemented citizen identity solution, and the recent report does not offer an update on that total.
But, this week’s report finds that 38% of respondents are still using a federated or hybrid model. Another 21% said their state’s identity system was decentralized and agency-managed, and 9% reported other approaches to identity management. The respondents could select multiple options.
So while many states are trending toward establishing more centralized and citizen-controlled statewide digital identity infrastructures amid these evolving threats, the migration to this unified system has been slow. State tech leaders cited a combination of organizational, financial and technical challenges, with migration a primary challenge itself. To institute a new login system, officials must reconcile years of independently built agency identity systems, the login and personal data those agencies possess, siloed governance and policies, and agency ownership structures.
And to do this, state leaders said they need funding and cooperation from those agencies. In fact, 70% of respondents said inadequate funding or budget for an enterprise identity solution was a challenge to implementation.
Two other challenges came in second place behind funding: 68% said fragmented or siloed identity systems and another 68% pointed to organizational or cultural resistance to enterprise approaches on the agency level. In third, 51% said technical debt was a hurdle.
To overcome these challenges, the report recommends that states begin to treat citizen digital identity as a core, statewide capability rather than an agency-specific function. This would involve establishing centralized governance and standards for implementation across agencies, and supplying sustained funding, stronger executive support and communication to build agency buy-in.
The report also encourages states to collaborate and prepare for emerging identity threats and technologies. Looking ahead, NASCIO also recommended that states continue to explore other identity management technologies — such as digital wallets, reusable credentials and self-sovereign identity — while continuing to balance security with privacy, accessibility and citizen control.