Advanced Communications and Information Technology - Joint
Video
Transcript
5 documents
Machine transcript
May contain errors. Verify important quotations against the official video.
About transcript accuracy
- Source
- Whisper
- Model
- ggml-large-v3-turbo.bin
- Processing date
- October 6, 2026
Representative Stephen Meeks
Unverified
0:30
All right, colleagues, I've got 1.30, so if everyone wants to kind of settle in, we'll get kicked off here in just a minute.
All right, everyone, we're going to go ahead and get started with the joint advanced communications Committee meeting. This is
our first meeting of this session, I think, this interim. So appreciate everyone being here on a Monday. First thing we need to do in order to get started is to approve the minutes from the April 23rd meeting. If I could have a motion for that. Okay. We've got a motion. Second, all in favor say aye. Aye. Any opposition? Okay. We'll consider that approved.
Next, I need a motion to authorize the chairs to approve special expenses incurred by the committee during the interim, if I can get a motion for that. Okay, motion second. All in favor, aye. Any opposed? Okay, we will consider that approved. All right, colleagues, we're going to jump right on into this. We've got several important items we're going to discuss today related to technology. As you all know, this is a very fast-moving field. What I'm going to do without objection, I'm going to take item F out of order.
We've got folks from Delete Me are on video. And so instead of making her wait through all the other discussions, I'm going to go ahead and let her go first. So I first heard about this company back in February when I was at an NCSL conference. And I'll let her get into the details of what they do. But based upon that discussion and what's been going on in the world, I felt it very important and timely for us to learn about what they do,
why it's important, and why we should consider this not only for the legislative body, but all the other elected officials within state government. So with that, Ms. Tevener, can you hear us okay? I can, yes, sir. All right. So if you would just introduce yourself to
the committee and the floor is all yours. Hi, my name
Taylor Tabner
Unverified
3:20
is Taylor Tabner. I am with Delete Me. We are working to help protect legislators, state officials from threats, harassment, things like that.
Speaker 11
3:29
But from here, I'd love to jump into a PowerPoint presentation if possible. So I will go ahead and share my screen now. You guys let me know if you can see it.
Senator Breanne Davis
Unverified
3:43
We've got it. Perfect. Okay. So realistically, what I'm here to do today is really just to kind of help
provide you guys with an additional level of protection, because what we are seeing more than anything is that exposed data is creating real world risk. You guys are not immune to that, probably a little bit more susceptible. So what I'm hoping to do today is just kind of show you what's out there,
how we can help and answer any questions that you
guys may have. So a little backstory about us, just so we can
kind of set the scene a little bit. First and foremost, kind of wanted to give you an introduction to DeleteMe. We are a data privacy company. We actually work to remove personal information from data brokers from the open web. So think things like Google searches, things like that. But why this matters and why we're here today and why Representative Meeks brought me on was because that 84% of state legislators really have reported being insulted, harassed,
or something within the past year or so. On top of that, kind of double clicking a little bit further, it continues to get worse. 44% of those, 44% of your peers, probably some of you guys in their room have been threatened. I mean, that's not just you, that's your families. And that's really where we kind of come into play. What we see here is when we're talking about severity of threats, you know, and what I will say here more than anything, is that it's not really a threat. You know, I think a threat implies that it may or may not happen.
I think this is a true risk because what we do see more than anything is it's not a matter of if, it's a matter of when, and it really is a matter of to what extent. I know there's been incidences in the state here. I worked to kind of cover from Delaware down to Florida and over around Oklahoma. I can't tell you a state that hasn't had some sort of incident. So we'll leave this here and you guys kind of review it at your leisure. I know you guys have this printout as well, but this can vary. You know, the severity of threats, the severity of risk is anywhere from true death threats to swatting, to doxing, to threats to your family, to death in a lot of these scenarios.
You know, if we think about the tragedy that happened in Minnesota not too long ago, what we will see is that what ultimately is causing this is these data brokers. It is the exposure of PII. So here, what we're looking at, this is the affidavit from everything that had happened in Minnesota. This is public record. This is not us pulling it. This isn't confidential. This is, again, public record. What you will see here, though, is these are all common data broker sites. These are all common people finder sites. So for you guys, for other elected officials, for judges, for anybody really on the public sector side of things that is public facing in some regard, this is even more damaging because these are as simple as, you know, understanding and knowing somebody's first and last name in the state that they're located.
Well, for you all, when you are representing the state of Arkansas, that is public knowledge. So what I will do from here is I'm actually going to switch over to a site called Family
Tree now. This is just the simplest example of what I just outlined on the previous slide
Speaker 11
6:51
and show you how easy it is to really find any of this information. So bear with me one second as I switch over. One second here.
Senator Breanne Davis
Unverified
7:04
Okay. And so here, making sure we're looking at Family Tree now, this is that simple site, right? This is all public knowledge. This is a free site. So it's not behind a paywall. We're not asking for any credit card information. They are not either. I'm going to show you my grandfather. He is a public, he's an elected official in Virginia as well, or was a while ago. But when we're thinking of peers, thinking of similar exposures, this is what you guys are working with.
So again, all you need first, last name and state for you all. Everybody has all of
that already. Click search records. We'll give it a second to load. He is going to be this third one down right here. We'll click view records. We
can click out of the ad. So first and foremost, he knows I'm showing this. He actually wants to use this as an educational touch point really to kind of help Just spread the word. So for you, when we're thinking of, you know, you have constituents, you have somebody that doesn't like the bill that's being proposed, doesn't necessarily like some of the support,
whatever. First things that we see here, the first thing that pops up is your home address. This is a hyperlink. This takes you to a Google map, helps individuals find exactly where you are. So when we're thinking of incidences, even as simple as a swatting standpoint, right? They know where to send them. They know where to have these calls routed. But when we think of a little bit further and a little bit broader, think of like a Daniels Law situation or the situation in Minnesota, we have people showing up. And what we see on top of this, as we're working with a lot of FBI agents or as we're
working with quite a few to talk about mitigating some of this risk, what we see is we see individuals, we see the bad guys take this information and they idealize the attack. So they're looking at the layout of your home, where you and your family are sitting for dinner, what have you. All of that starts with a simple exposure of PII. Go down a little bit further, got
Speaker 22
9:03
your phone numbers. This could be a variation that could be your cell phone number, could be your phone number at home if you still have one. In some scenarios, it could be your work number, what have you. It's all right here.
Senator Breanne Davis
Unverified
9:16
Now, what I would love to double-click on here, which I think is even more important, not that it's more important than you, but equally as important, this is all of your family member's information. So this could be your spouse's name. This could be your kid's name, specifically if they're over 18. And everything that we just saw for you, we'll see for them as well. Now, one thing that we hear often, specifically when we're working with public servants and elected officials, is that you guys signed up for this, you know,
and you guys have a duty. Some regards, I agree with that, right? Like, but you didn't sign up for this and neither did your family you know and so we're not looking just to help you protect yourself but those closest to you because again two data points which is public knowledge there is an ample amount of exposure there i'm going to stop there i'm going to kind of piggyback go back to the previous slide that we were just looking at and we'll answer any questions in the next little bit and while
Representative Stephen Meeks
Unverified
10:17
she's doing that colleagues if any of you have your laptops with you i would
encourage you to go to that Family Tree Now website, type in your name, and you can see all the information that's out there publicly available about you and your family. So back to you. Perfect. No, thank you for
Speaker 22
10:34
that. And what you guys can do too, I think you have the printout. That is the QR
Senator Breanne Davis
Unverified
10:39
code. You guys are welcome to look there. Also happy to send out whatever you guys may need just so you can search that. But the best way to protect yourself is to know what's out there to start. So I would 100% recommend starting here. This is the simplest way to find
out what's out there. Another great way is to do a quick, you know, an easy Google search. You'll see all those populations. A Gemini is great as well, because what it's doing is collecting any of these touch points that are out there for you and putting it in one centralized location. But, you know, I think the starting point for you all in this scenario is knowing what's out there. So then we can then look at preventative and proactive solutions to help remove
it. Not going to spend a ton of time on this slide, but I just want to
call out that you guys aren't the only ones
looking at this. We do have a footprint in over 30 states, specifically on the public sector side of things. We actually have some in the state already in Arkansas. We're working to protect the judiciary there. But looking a little bit broader, there's coverage nationwide, constantly changing. All of this to say this is a public sector solution. It is more important now than ever. Not going to get super in
the weeds of this, but do just want to kind of talk through how this approach works. Realistically, what we do,
so we've talked about Delete Me High Level. It's a
data privacy company, what have you. But the long of the short is that we actually go and we work to remove all of your exposed personal information from the open web. How we do it, a couple of different ways, but realistically, we do it to ensure that we are protecting you. So there's a lot of automation we do it so we can keep
up with these changes at scale because one thing that we know is like we're constantly exposing ourselves right like we're in the age of technology we're all using our phone we're doing a door dash if we're working late in the office we're the convenience
of an amazon to send stuff home whatever especially during busy seasons during sessions where we're all you guys in particular
are working late to get things across the finish line we understand that we're exposing ourselves so how we do this is we leverage our automation to go and scrape find any potential matches for you all then we have a team that actually goes through and fact checks it the importance of that is we want to make sure that we're protecting the right people you know because if we even go back to the previous example that i showed of my grandfather right there's multiple different variations it's a probability thing at this point it's highly
likely that somebody has the same name as you somewhere in the world we want to ensure that we're protecting the right people right if we're protecting a senator jones but it's not the right one who are we protecting what have you those sort of situations that was just an example especially with the common names we need to make sure we're doing our own due diligence so in this process there's automations there's a human component going through going through this process of actually ensuring that we are removing the right information for you and ensuring that
it stays down the other thing to double click on there is that we have the process fine-tuned But what we see a lot of times, too, is as legislation changes or what have you, there's a reporting component that needs to be included as well. You guys will have access to that. It's in your own privacy advising center. It's also one of these things that will be sent so you guys can know more, do better. Again, one of these things, the more you know, the better you can protect yourself. We won't get into the platform and the partnership today, but happy to double-click on that in a later date if needed.
So these are just some quick examples of before and afters of what you would expect. This just kind of double clicks on what we looked at previously. So this is a very, very common people site. This is Radaris. 99% of people are going to be on here. On the left is what you would see prior to a service or prior to anything from a data removal standpoint. You're going to see it out there. You're going to see all of it out there. After the fact, you're just going to see a lot of this gone. Same thing here when you're looking at searches on Google.
Again, going back to kind of understanding what's out there, most everything is out there. Nine times out of ten, if you have a constituent that's angry or, you know, somebody that's looking to potentially harm you and your family, they're going to a Google before they go to a tax record site. Before they go to a data broker, they're going to Google first. So why this is important here, and not even really to get in the weeds of this, but there is a component with the delete meet where we actually go and we clear out the Google cache, meaning that we're not leaving any breadcrumbs.
So you guys truly will have a pretty clear digital footprint, and it is constant, right? Again, we're constantly exposing ourselves, but we are constantly working to protect you all so you guys can keep doing the good work that you guys are doing for the citizens of Arkansas. Super, super important feature here, specifically for those on the legislative side of things. This is something we also do all elected officials. We're doing a lot of it with the judges already. We can obviously continue to do more of this at scale.
We'll do real estate listing removals. So think of a Zillow, think of a realtor.com, because again, you guys are public servants, but you don't need to bring that home and you don't need to bring these people inside of your home. So protecting you guys in a way that allows you to continue to do your job, but does put up some boundaries and some parameters in place for you and your family. Same thing here with a street masking view, essentially working with Google Maps to blur out your home, making it a little bit more secure. Again, allows you to not go from side to side, see the interior, see the
exterior, understand the angles, what have you. This is just an additional way in which we are working to help protect you and your
peers. Now, we'll stay here for a
second because there's a couple of different things to talk through here. So realistically, my goal for this conversation is just to really provide you guys with more solutions to help protect yourself. One, we have the tool, which is super effective, really important. The other thing that we have done is we've actually worked to help draft legislation. So we've seen this in Utah, it allows us to really kind of remove
all of this information for all elected officials, all public servants there. So what I will say here is when we're talking about this, there's a couple of different layers, right? The tool itself, I would say, is a short-term solution. The legislation is a longer play. But we were built to support it, and we can also help support it in other ways. But the benefit of this, and what I will double-click and say here, is that we are helping to protect you guys and your peers, but also broader. Think judiciary, think state agencies like Family and Child Protective Services,
Department of Labor, health and human services right now, the footprint is vast because we see that the climate and the landscape continue to shift based off of severity of threats, and we can help with that, again, tool and legislation-wise. Not going to really harp on this, but when we think of
how we can help, you know, the biggest thing I will say above everything is that we want to reduce your risk,
and this is something that I think we all can agree on, is the risk is out there. How do we
protect yourselves how do we protect your family and these changing kind of climates like what does that look like um and then secondarily too i know there is a cyber cyber security component obviously a technological component what we see on top of the physical and just the digital protection that we see on an individual level is that network security for organizations that partner with us or that we have helped really see significant drop in phishing attacks because the majority of the time the true metric is nine times out of ten it starts with a phishing a
targeted phishing attack from a cyber security data breach standpoint which starts from exposed PII cut the source protect things long term that's all I really have I really appreciate it I'm opening I will open up
Representative Stephen Meeks
Unverified
18:38
to any questions if you guys have anything okay thank you uh colleagues a lot of times these
these you know we've seen judges that have been assassinated we of course had colleagues in minnesota that were assassinated within the last year and a lot of those began with searches of this online information i think one of the stories and you may know the
details of this better where when the perpetrator went to assassinate the elected official the son or the daughter was with them and you know the story i'm talking about i do yes yeah that's daniel's law yeah why don't you go ahead and tell that story you probably tell it better than i can yeah so i actually
Senator Breanne Davis
Unverified
19:17
had the pleasure of a meeting with judge solace a couple months ago and hearing her story firsthand and it was one of the
most moving kind of scenarios that i've heard right like it's been several years ago and she can still kind of she still gets choked up
but essentially what it was it was right around covid her son daniel i mean even myself we're all guilty of it uses uber eats quite often and was having deliveries home and things like that well there was actually it was an angry prosecutor that didn't like the ruling that she had made found their information by a quick google search actually family tree now which we just looked at found their information showed up at their house shot her son daniel point blank killed him and then shot her husband as well fortunately he survived but rocked their world justifiably so
And so that was probably one of the first times that we have seen a lot of that really kind of really pinpoint the need and the risk for protections for exposed PII since that. And as a result of that, there is the federal the federal jurist or federal judicial legislation. That's Daniel's law that works to protect all of the federal judges there. We're seeing a lot of that rolled out at state level as well, but also like similar incidences in Minnesota. I can think of the exact same situations in Maryland, quite a few other states.
That's probably one of the most common ones, but it unfortunately happens all of the time. So the more proactive and preventative
Representative Stephen Meeks
Unverified
20:47
we can be, the better it is. Thank you. And again, colleagues, this is not about limiting public access to us. It's just making sure that the data that we have out there is not going to put us in a situation where we could become the victims of some of these crimes. With that, does anybody have any questions?
Representative Brown, do you have the... Hit your button again. It's not showing up up here for me to.
Representative Matt Brown
Unverified
21:27
There we go. All right. Thank you very much for your presentation. When you were speaking, I pulled up a couple of websites, and there was nothing on the first one, and I thought, oh, well, my ID theft protection is working. Then I checked it on another site, and my name did not come up,
but my deceased husband's name and address, which is my address, um came up and uh that's very concerning and probably some of the names of his children also were there i don't i didn't look that deeply but anyway so would your service uh look for spouses names and children's names and things like that yes ma'am so included in the coverage
Senator Breanne Davis
Unverified
22:14
for yourself specifically on the legislative side
things we protect your family members as well so it's not just you it is next of kin because what we understand as well is like while there may be some gaps in coverage or while you may have you know just some initial searches that aren't um showing up for you or what have you we understand that the connective tissue is just as exposing right so like in reference to the relationships that you just brought up like what we see too specifically from a risk standpoint is that if you guys are clean typically they'll go to the next connective tissue so a lot of times if you
know like you guys are safe protected that information's gone they'll go to the spouse because that's the next way to reach you same thing with the home address that you're still living at so the short answer is yes ma'am we will work to remove that information as well and there is no limit so what we will do is like typically it includes spousal coverage that can be there's some variability in that but we also want you to provide like hey like these are the connective tissues this is my mom dad brother whatever we'll work to kind of cut those ties and ensure that you are protected from that exposure as well thank you yes ma'am okay
Representative Andrew Collins
Unverified
23:25
representative collins you're next thank you and i actually use the service personally so i i mean i definitely see the value of it um the reason i did it was just kind of to reduce the amount of information that was out there, I kind of felt and recognized that there's no way to really get rid of something. You know, my data is going to be out there in some way at some point. It's a game of whack-a-mole that we will lose. But I would think that's even more true for a public official
where there's even more information. And if there's a situation where somebody is really trying to get that information, I would think that they're going to be able to get it. And so i guess i'd like to know your response to how your service offers protection given the reality that if somebody is targeting a specific person there's probably going to be a way to get a lot of the information that you guys are reducing the overall like instances where it's out there and i appreciate that but not really you can't really scrub most of that i mean it's on public records
and other things that you guys can't even get to? Sure.
Taylor Tabner
Unverified
24:35
Yeah, I think there's two answers to that and two solutions. So I'll answer
Senator Breanne Davis
Unverified
24:39
it in two different ways. So one, specifically for you all, and in comparison to the consumer plan that it sounds like you may already have, specifically on the public sector side, we also leverage humans. So we have the automation, we have the automated opt-outs, which kind of gets some of that low-hanging fruit. It's pretty similar to what you have on the consumer side. But on the public sector side of things, So, thinking of judges, thinking of you guys, we leverage a dedicated privacy advisor. So, they're going to the hard-to-reach data brokers. They're going to these hard-to-remove-from-sites and actually actioning on your behalf. So, in that regards, we see a significantly higher success rate.
But on top of that, what that actually allows for is we have what we called an incident response sector of the public sector team, meaning that you guys are never sitting in a queue and say you guys know that you're in session and you want to bump up protection. You give us that heads up, and we go and we go to those sites proactively, even outside of our typical realm, and we go and we work to remove that on your behalf to ensure that we have as much of a proactive response as possible and as much of a preventative response, right? because to your point like if somebody wants to get you or get to you they're going to try they're
going to try all these measures they're going to do all these things but the cleaner we have that footprint the better it's going to be and what we can do on the public sector side of things that we've seen significant risk improvement on especially when looking at a consumer side is that proactive threat response and that incident response so that's one but in regards to tax records and some of those government sites and what have you so without legislation you are correct we typically we can submit it as a custom request which also is kind of an added feature of
public sector side of things and we do see a lot of i would say wiggle room there but that's not a guarantee legislation is the long-term play so this is the short-term preventative play making sure we have your footprint as clean as possible legislation is what really really sets those parameters in the long run okay thank you do you have
Representative Stephen Meeks
Unverified
26:48
a copy of that model legislation you can maybe email to us and we can make it available to the committee members okay perfect absolutely
okay uh representative richardson you're
Speaker 64
26:59
next thank you mr chair um thanks for presenting this interesting information. One of the things that I experienced in my professional life is a challenge associated with dark web entries or that data sitting in those locations that are unavailable, continuing to repopulate and bring that data back to the forehand where it's easily accessible from a consumer perspective. I'm curious if your tool is, if it's just a reactive
associated with that or are you actually working with some of the back players like while on or whoever to try to
Speaker 66
27:34
remove that data what is it what additional steps are you using from a from a
Speaker 22
27:40
dark web perspective so long and short there's again
Senator Breanne Davis
Unverified
27:43
two approaches to this one typically we focus on the open web specifically for individuals like yourself because what we see is in a lot of a lot of ways like if we're focusing on the dark web we're actually missing what's right out there in front of us. However, we do have partners that if that is sort of a necessity that prioritize
everything on the dark web for us, and they're monitoring things like that, where it gets a little bit dicey on the dark web is you actually can't truly remove it because what you would have to do is purchase batch data and sort of hope that your information is in there. What we don't do, we don't typically do that. We do have partners that do it, but what we try to do is really maximize our impact on the open web and leave that to the partner side of things if that's a month okay
Representative Stephen Meeks
Unverified
28:33
thank you yes sir do you do you have any data or anecdotal stories uh that compares
legislators who or states where your service is currently active where you've done the scrubbing and cleaning versus those who are exposed on the web i guess looked at the difference between those two groups to see have you noticed has there been any decline in the number of threats or harassment just curious if you've noticed
any difference kind of before and after yeah absolutely and i'm happy to share
Taylor Tabner
Unverified
29:05
some of those examples i'm happy to send them over for
Senator Breanne Davis
Unverified
29:10
and distribute if that's helpful. But there's a couple of different easy ones that sort of come to my mind. And I would say it's twofold. So one, specifically as I'm thinking out about a particular judiciary, but you guys have very similar threats. We actually have had the judges advocate on our behalf because of the lack of attacks, lack of threats, and how much that is done from a morale standpoint. They actually use that as a justification to expand coverage in the state outside of the typical judiciary. So that's one that comes to mind, but also when I'm thinking
from a cybersecurity standpoint and a framework standpoint and security posture within the state and the organization, there's one that comes to mind for me in the state of Utah, where we were working with one of the IT individuals, and he was the one responsible for escalating issues as they came in, specifically on the personal side of things. And one kind of data point that he gave me, which I wasn't necessarily thinking, but as I kind of take a step back and think as an IT
professional, it makes sense. He was saying, you know, the lack of, or we've seen a significant decline in the number of threats that individuals have seen on a personal level. What we have seen though, is we've seen, we've been able to monitor our systems better. We've been able to isolate and pinpoint the attacks better. So we're not seeing these incidences go beyond, you know, the Capitol or the courtrooms or any things like that, we have those security parameters in place, right? Like you guys have systems in place as you guys are there. Where it gets a little bit
broader is the second you step outside, what's happening at home and those sort of things. And so when we're thinking of that is it allows us to pinpoint and to kind of redirect some of the threats to the place where we have the security measures already there. And we allow this to kind of work as an additional kind of expansion of those protections to your home, to you guys on the personal level. So it allows you to do things, you know, just with a cleaner peace of mind or clearer peace of mind, and you're not having to look over your shoulder as much. So I'll send those over, but several different use cases, you know, when we're looking at morale and
we're looking at true threat risk, when we're looking at things from a cybersecurity standpoint, we have them. And
Representative Stephen Meeks
Unverified
31:26
I would love to share those data points with you. Okay. All right. Awesome. All right. Colleen, any other questions? All right, Ms. Tavenner, thank you for being with us today and for presenting this information. Obviously, it's a growing concern. There's probably a lot of good people who would consider running for office but don't because of this particular issue.
And so as we go forward into the future, I wanted to let the committee know that, A, that this service is out there, Let everyone understand the risk that is out there by us not taking these proactive measures. And for us as a legislature to strongly consider moving forward on something like this for ourselves and for the rest of the elected officials within the state. So once again, thank you for joining us this afternoon. Yes, thank you for having me and thank you guys
Speaker 22
32:21
for all the good work that you're doing.
Representative Stephen Meeks
Unverified
32:24
I really appreciate it. Thank you. Have a good afternoon. All right, colleagues, we're going to switch gears here now. Tell you what, item D and E is going to be related to cybersecurity and AI. And I think you all have kind of a singular presentation. So a few gentlemen, why don't you just come on up together instead of coming up one at a time. And we'll let you get settled in there. And then you can introduce yourselves to the committee.
the brand new office of state technology They're not coming on.
Exactly. These only thing happens, these things only happen at a technology committee meetings where we have these technology issues. Yeah.
Speaker 85
34:08
All right. Yeah, Jay Harton, Director of Office of State Technology and also the State Chief Information Officer. Good afternoon.
Speaker 86
34:18
I'm Robert Magoo. I'm the State Chief Data Officer and Chair of the AI Center of Excellence. Good afternoon. My name
Gary Vance
Unverified
34:25
is Gary Vance. I'm the State Chief Information Security Officer. Okay. Gentlemen. All right.
Speaker 84
34:32
Thank you all, everybody, for having us here. I think it was back in January of this year was the last time we kind of gave some updates.
We've had a lot of legislation passed. Thank you all for that through the legislative body through this last session. Three key pieces of that legislation was Act 480, which gave the Office of State Technology IT governance over the executive branch. And then also Act 489, which was the Cybersecurity Act. and then also act 375 which created the data stewards that each of the executive branch departments have to define to help with robert and his team's goals out of the i'll be talking
about the act 480 and then gary will talk on act 489 the cyber security and then robert will be on act 375 with ar data so primarily out of the it governance one of the main things that came out of that legislation was to give us oversight of all IT procurement within the executive branch departments so from that we created a process called the technology and investment justification so any IT spend across the executive branch has to come before the office of state technology
for approval and review so what does that mean so that means that once they submit their procurement that they want to go through it goes through several what we consider gates within the office of state technology so first it's reviewed by our enterprise architecture team to make sure that you know it's not some crazy one-off service or something like that or also to see if we already have a service that's already offering that level of offering of service to the constituents or to
the other departments to make sure we're not being duplicative in services and we can also use that buying power from there it goes to Gary and his team for a cyber review cyber governance review and then so from his perspective they look at it to make sure that it's a secure solution that they're meeting all of the state security standards and then the next gate that it hits is Robert's team for a data management to make sure that if they are entering data into this,
that from our perspective, we own that data, and that if we get, you know, something happens with that vendor or whatever, that we control that data, and they don't own it at the end. We want to make sure that we're protecting the state citizens' data and the state of Arkansas data. So once it goes through all those gates, then it comes to the Office of State Technology leadership team for review and approval. So that's for any IT procurement that's a million dollars or less. If it is over a million dollars, then it goes before an IT governance team.
And that IT governance team is made up of the secretary from Department of Finance Administration, the secretary of inspector general, Jessica Patterson, who's the director of Office of State procurement and then myself and then we have a rotation basis of three CIOs from each of the different departments right now they're serving a one-year term on that so currently it's the department of human services CIO department of commerce and department of labor and licensing
so those three CIOs sit on that and we meet every two weeks we don't want to slow down any procurement process so we're meeting every two weeks to get those through all the different gates so that we can, you know, move forward and not slow anything down. Also out of that became the approved hardware list. So we're looking at the executive branch just like Walmart and Tyson and all these big corporations look from a procurement perspective. So currently, prior to
this, and it's still ongoing, we haven't, can't do a full replacement endpoint. So your laptops, your desktops your monitors were all over the place they were lenovo they were hp they were dell they were asus all these different vendors and so what we've put out is an approved hardware list on our website that the departments can purchase directly off of and those don't they still go through the tige process but it's a it's a quicker tige process or technology investment
justification process because they're on this approved hardware list we do allow for exceptions there are some you know tablets or some your communications departments really like apple products so they like the macbooks and stuff for the graphics so we do have an exception process for getting things that are not necessarily on that approved list however looking holistically if you look at 22,000 roughly executive branch departments, those exceptions are maybe going to
be a 5%, maybe 10% at most. So you're looking at spending, you know, with one vendor for those endpoints, you're going to drive that cost a lot cheaper than, you know, somebody making an agreement with HP this year, and then somebody with Lenovo the next year. So the next big thing that came out of the governance as well as a project management office so we're in the process of actually standing that up recently we just hired on a new project manager that's going to
lead that group so that ties into the technology investment justification so we haven't well there's a couple projects that have been submitted and approved through the technology investment justification process however those are out for rfp so once those go into once the rfp is awarded the department will have to assign a project manager specifically to that project but then they're going to have to report back to us in our project management office to
make sure that they're hitting their timelines their goals their procurement all that kind of stuff they're going to have to report that up to us so that we're making sure that they're keeping on track and not, you know, a whole lot of change requests or anything like that so that we can start really making sure that the scope of these projects don't, you know, go off the rails and that all the timelines are being met. And then the biggest thing out of the IT governance, I think from my perspective at least, is
our ServiceNow implementation. So ServiceNow, I call it to IT people, ServiceNow is like SAP to the accountants and everything like that so it's a platform um for it people to be able to manage incidents problems um all those type of things so when your desktop or laptop doesn't work you can either call into the call center open a service now incident you can email into the call center and it'll automatically open a ticket so that's that's kind of phase one of it the next phase that we're going to have is that
that we'll have a complete inventory of all hardware within the executive branch, not only just endpoints but TVs, switches, network switches, and everything like that. So when an entity goes to do an upgrade on a system, they can say, hey, I'm going to do an upgrade here, and we can see what systems are impacted by that. So that's going to be the next big thing from ServiceNow. We're in the middle of that RFP for implementation services.
So we're hoping we should have that before the ALC review committee, hopefully in November. Now this one I think everybody from OST is really proud of. From an IT assessment, we finally, as of last week, maybe the week before, we actually have a full inventory reported by the departments of the applications that they are running within their department.
I think that's probably the first time we've had something like that since probably 2006 or 2007. We're, of course, going through that data and normalizing that data. You know, we have both ends of it where, you know, somebody reported that we're running four versions of iTunes to where, you know, some person or one department just said we're running iTunes, which is fine. We have to normalize that data. So now that we have all that data, the next phase of the IT assessment is getting the infrastructure inventory.
So we're going to work with the partner to go in and see what all server hardware, what kind of storage and all that kind of stuff, and look to determine the age of that equipment. Is it best to just let it age out in place, move it to one of the state data centers, or just migrate that into an existing service that the Office of State Technology already has. And so we hope to have that completed by the first of the year.
And then follow up on that, we'll start doing an IT skills assessment. So as we start bringing these things into a centralized area, we're, Office of State Technology, are going to need the assistance of these IT workers than the other departments to be able to help support these systems and applications so we're going to work with the partner to do a skills assessment across all the executive branch it
workers to see what skill sets we have we know that there's quite a few that are retirement eligible not only from years of service but also age i think within of the 130 office of state technology employees i think we're running about 20 that could retire today so we want to make sure that we're feeling backfilling those positions and getting people up to speed so that they can you know move into those positions as those people retire out
and then one other thing the last thing that i'll talk about is the consolidation plan so as we're gathering all this information we're working on putting together a consolidation plan so the office of state technology already has roughly about 10 shared services that we offer to the other departments and so part of the consolidation plan is how do we bring those departments that aren't on our shared services onto that so that we're using one system a good example that is
enterprise backup so today some of the departments are doing their own enterprise backup at their location and then you know it may be replicated into the cloud it may be replicated into one of our data centers but the big thing is to get all of that centralized we're all using the same system So that if there is a disaster or a ransomware event or something, there's that knowledge and expertise that we can restore quickly.
And then the IT contract. So as we start looking at these application inventories, you know, one that we've looked at real quick is Adobe. Everybody's using Adobe for PDF reader and that type of stuff. So we're going to look to work with Adobe to create a statewide enterprise contract so that we're sure that we're all getting the same pricing and the same level of service from
Representative Stephen Meeks
Unverified
46:25
Adobe. So a lot of this was actually Representative Richardson led the charge on this, and I appreciate it because there's a lot of good things going on in this space.
And obviously, I know it's very early on in the process, but it sounds like it's already starting to bear fruit for the state. So I appreciate that. Before we move on to the next part of the presentation, does anybody have any questions regarding this aspect of it? Representative Richardson.
Speaker 66
46:54
Thank you, Mr. Chair. Surprisingly, I have questions. So, yeah, so you
Speaker 64
46:59
mentioned staffing as a bit of a concern. 20 or so people that are going to be aging out um i'm sure you have normal turnover just like
everyone else are you finding it difficult to backfill those positions uh is the current pay rate acceptable those kind of questions i'm curious about um i will
Speaker 84
47:18
say this with the new pay plan um some of the positions that we've advertised we are seeing what i would consider record numbers of applicants um so i haven't been doing any personal the personally any of hiring or anything but the lower level managers within office of state technology have said that they're getting a lot more qualified candidates
Speaker 64
47:41
excellent good uh you also mentioned um backups
and off and i'm kind of going to reverse order of my questions so and hopefully uh mr chair you'll you'll let me give me a little bit of latitude um so uh yeah backups um one of the big challenges that we've seen with ransomware is their ability to actually get in and delete what we call online backups, right? So I'm just curious, in your plans as we kind of move forward, are you looking at the ability to provide an offline, is that already a requirement,
Speaker 84
48:13
air-gapped backup environment? Right, so currently with the Office of State Technology, what we offer, so we're doing
disk to disk backup so we're doing that and then well probably the last four years we've still been spending that off to physical tape because they can't get to the physical tape right right so we've been doing that and that's one of the main reasons why we want to get everybody on this service is so that we have that air gap of you know so the ransomware people can't get to those tapes
Speaker 64
48:46
and delete the backups or encrypt them as well okay thank you last question for me the the office of PMO so you mentioned that that's not up yet I
know that's a big piece of bringing all this together and making sure that we can manage that making sure that we have a published agenda if you will for an annual basis of what you're going to try to accomplish what types of projects
Speaker 84
49:12
are going to be approved and whatnot when do you feel like that that's going to be coming online I mean so the office of state technology we internally had four to five project managers that just kind of handled internal stuff so there we're transitioning those resources as well over to the larger pmo i would probably say the first quarter of 2026
we'll have that in place the person that we just hired has been working at axiom for a long time And so we're really happy to bring him in because he has a lot of experience, not only from just IT projects, but standing up a project management office. Okay. Okay. Thank
Representative Stephen Meeks
Unverified
49:55
you very much. And I know it's extremely early in this process, but are you getting any kind of sense of what kind of savings, if any, that the state will realize by pursuing these initiatives?
Speaker 84
50:08
Not really yet. we are seeing um so the the approved hardware list that we have out there that's like if dell is the preferred or is on that hard approved hardware list and with the just with the three months that we've had it out there we've already seen them that well let me back up real quick so that approved hardware list is if i went to dell and bought one right that's the lit that's the price that i get um we've already seen um with the volume that we're getting through dell they've
already come back to us and lowered that cost um by fifty dollars a unit um so we are seeing some gains in that um and i know like department of corrections they have a fairly big procurement that's um that's going through the technology investment justification to replace endpoints so we'll i'll be curious to see what um that pricing comes back with um but we're we're just not quite there yet okay
Representative Stephen Meeks
Unverified
51:03
all right all right seeing no other questions we'll move on to the
Gary Vance
Unverified
51:10
space. Thank you. Good afternoon. So as Jay mentioned, we've been very active and we've got
a lot of work going on and a lot of good work. I wanted to focus on what we're doing in the cybersecurity area and in the two areas of the centralized cybersecurity office, which is part of Act 489 and the legislation, and then some executive level cyber initiatives that we currently have in flight that are directly tied to Act 489 as well. So the first area I would start with is on our cyber policies.
We to date have been able to centralize approximately 20 cyber security policies that have gone through a review and approval process and are considered to be our approved state policies in those areas. We've also identified roughly 200 cybersecurity controls that we will use across the executive branch, so we will standardize on those cyber controls, which in a moment I'll tell you
why those things are important as we begin to develop a standard baseline across all the executive branch where we're operating under a set of common policies and a set of common cybersecurity controls. That's going to be very important for us going forward. For the functional alignment, that's also part of the legislation as well. So what we've done to date on this is we've created what I call a virtual CISO for each executive department.
That virtual CISO will align with the state cybersecurity office. We will align those individuals with governance. We will align those with standards as we get ready to implement standards across the departments. They will be the go-to person, if you will, out of my office into the departments. And in addition to that, we've identified roughly 20 to 25 cyber resources
that exist today across the executive branch. So we're going to work through the V-CISOs. We're going to work directly with each individual department, and we're going to assess those skill sets, and then we're going to work to align those skill sets not only to perform the duties that they're currently responsible for in their department, but also to align with state cybersecurity objectives in areas like threat management, compliance, governance, and the policy work that we're doing as well.
So that will become our functional alignment as it's identified in the legislation. We have the V-CISOs in place today, and we're going to be conducting those meetings with those V-CISOs starting later this week going into next week. And that should give us our functional alignment into the state cybersecurity office. And that will be pivotal as we go forward then.
We'll have a single centralized unit, if you will, of cyber professionals that we can really begin to then drive the governance, you know, down through their departments and the consolidation that we'll be working on once we get that function in place. The next area are the cyber initiatives that we're currently focused on that we're considering a priority for what we're doing now.
And the first one of those is centralized endpoint management detection and response. So our goal there is that we will have advanced endpoint protection and monitoring in place for every user endpoint and every server in the executive branch. This is important because it creates a single view that we would now have through my office that we can now assess risk. We'll have an individual department level of risk
assessment, and we'll also have an aggregate risk assessment of how we look as a state across the executive branch in terms of what our threat landscape looks like, where our adversaries may have opportunities to exploit vulnerabilities, and it will also give us the visibility to see some of where those vulnerabilities are in advance so that we can mitigate some of those. In addition to that, it also puts a 24 by 7, 365 monitoring platform in place across all the executive branch.
It will be monitored 24 by 7 by 365. The service will be or is capable of instantly blocking known signatures and known profiles from a threat adversary without any interaction from anyone on our team. If the threat is, you know, seen on one of the endpoints, the service will automatically isolate that endpoint
to where there's no threat of, you know, proliferation or, you know, a threat, you know, extending through our environment. And, again, this is done without the need of someone on a screen. This is part of the service that's built into the tool. That's a big plus for us from a 24-365 standpoint because it's a material positive movement in threat maturity
and security maturity for the state. In addition to that, we're also working on a risk assessment process. And the purpose of the risk assessment process is we're going to take the threat data and the threat information that we collect off of the endpoint tool and we will use that telemetry data to feed into a risk management tool that will create a risk scorecard by department and, again, as the state as a whole.
It gives us a laser focus on risk and where our highest risk is. And it lets us develop a very precise mitigation plan to go and mitigate those risks, you know, ultimately reducing our risk at the state level. And so this is something I think is going to be very important as we mature our risk posture and our maturity of cyber posture.
going forward. Identity threat protection. Over the last two years, identity threat has risen to the top, especially in state government. And Arkansas is not immune to threat compromises and identity compromises. We're seeing those routinely. In some cases, several up to more, you know 10 to 15 in a week where we're having uh individual individual user um identity um
compromises um as a part of our centralized endpoint we're also building in an advanced identity threat monitoring uh process in that as well that gives us quicker insight into when an identity could possibly have been compromised. We see a lot of attempts on a single identity coming from multiple parts of the world, not just in the U.S., and those are really quick indicators that we know we've got a problem, and we can act on those a lot quickly.
the quicker we can isolate the identity and reset the credentials on that person's account, it's a step forward for us in protecting that turning into a business email compromise, which can be costly in some cases for fraud and financial reasons. And we mentioned earlier, I think, Representative Richardson, you brought up the dark web monitoring.
We're also going to incorporate a dark web monitoring process in this endpoint tool as well. And what that will do is it will give us an advanced look of do we have identities out on the dark web of state employees so it gives us some insight. If we can see those, we may not be able to remove them, but we can make sure those accounts are reset and the credentials are reset, and that will be another layer of identity protection that we will get as a part of our endpoint protection.
The last thing I'll go over with you is incident response. We are working to develop what I would call a statewide cyber task force. And the purpose of that task force would be for us to improve our readiness and our response readiness. In the event that we do have an event or compromise, we will have, you know, a trained incident response team in place that, you know, that can quickly respond to any number of a level of events or cyber incidents.
But the main thing it does there for us is it speeds up our readiness and our preparedness so that we have a team, they have the tools, they have the skill sets to properly respond to an incident in the event that we need to do that. We are also working with General Bridges and the Arkansas Guard to incorporate the Guard into this task force. We've had already two or three meetings kind of pulling together
what we think a draft of that team might look like, so that's ongoing. But, you know, we hope to get that completed early next year so that we have that team in place. The team will be representative of individuals from each of the departments, especially the larger ones. And then we, you know, we will look to grow that team and to picture a cyber command, if you will,
a centralized cyber command that would be there on the ready to handle not only day-to-day cyber-related incidents, but also something more serious as a cyber event that we would need to respond to either through Adam. You know, if the emergency cyber plan were to be initiated, this team would be in a direct response to the ESF-16.
And I think that covers everything I wanted to talk to you
Representative Stephen Meeks
Unverified
1:03:14
about today. Okay. Again, it sounds like a lot of good work going on. I have
two questions that came up. On the cyber risk assessment that you're going to do with each of the different agencies, I love that idea. The scores that you get from that, is that something that would be reportable to the audit committee? Because I know audit looks at a lot of this and there's some crossover between the two of you.
Is that something that could be reported to audit so that as these agencies are audited, that is made available so that if an agency is not coming up to snuff like they need to be, that they can be sitting here at the end of the table
Gary Vance
Unverified
1:04:00
explaining why? Yeah, so it's a great question, and that's absolutely what we're out to accomplish here. We want to, you know, appropriately, we want to put that risk out front so that we can see it, right?
We, all of us, can see it and understand it. It's not meant to embarrass anyone. That's not the purpose here. But you just simply cannot mature in cyber if you don't understand your risk. And so the goal there is to do exactly as you described, and that gives the visibility that we need. In some areas, we may need some assistance in that department. It could be funding. It could be tools. It could be a variety of things that we need to do to mitigate a particular risk.
Representative Stephen Meeks
Unverified
1:04:46
Okay. And then the second question I have is on training our state employees in
Gary Vance
Unverified
1:04:56
some of you are familiar with the SLCGP grant that went into effect a couple of years ago, I guess. And so, you know, the majority of that money is earmarked for local, for counties and cities. However, we get a 20% portion of that grant.
And so about 18 months ago, we stood up what we call the Cyber Center of Excellence. And so the approach there is to offer an opportunity to train state cyber resources by utilizing that fund. So over the past 18 months, we have offered a variety of internal cyber training from basic all the way up to expert. We've funded that with that grant money, and we've made it, you know, all you have to do as an individual is show up for the training.
We've had, over the 18 months that we've had the center up, we've had approximately 500 enrollees. going through a variety of courses over that period of time. So it's been very successful. We want to build on that going forward. We've got a couple more years of SLCGP money, and we're going to continue to use a portion of that money to fund the Cyber Center of Excellence. Excellent. All right.
Representative Andrew Collins
Unverified
1:06:24
Representative Collins. Thank you. Anna, this sounds great, and I think you guys do a great job. And I noticed that, you know, as it should be in your discussion, you're talking about the executive branch of state government. So I guess two questions. One, where do the legislative and judicial branches fall in? I know we have BLR and we have AOC. Are those considered to be legislative and judicial, respectively, or are they within your purview somehow? And second, and maybe my question I, you know, kind of dread having to ask because I'm afraid of the answer.
How are we doing with local governments, city, county, school board, et cetera? What kind of resources? I know it's not your purview necessarily, but how can we help bring them along? Because I know there's obviously lots
Gary Vance
Unverified
1:07:15
of gaps there on the cybersecurity side. There are, and the SLCGP money that I referenced earlier, that's where that money is going directly into county. and to cities. So we're making progress there. We're making improvements there, trying to follow, again,
a standard model for especially, you know, the heretofore the counties and the cities, especially the counties, they've been pretty much left up to the individual county to make whatever decisions they wanted to make in terms of cyber. And, you know, we've seen, you know, really severe third-party risks that get into the county with a provider that may not have offered the level of excellence in service that they may have indicated in the beginning.
I mean, you guys will remember when all 74, 75 counties were subject to a ransomware event a couple of years ago, and the primary reason of that was because of a third-party provider that had some vulnerabilities and risk in their environment that exposed the counties. So, you know, we're trying to make improvements in assisting with third-party risk and third-party risk management.
But it's making progress. We've seen less cyber incidents and events in the counties and cities maybe over the past 15 months where we were probably a little more active than we wanted to be with ransomware in those areas. You know, K-12 has particularly been a target for ransomware events. We've seen reductions there as well. We are improving our alignment with K-12 almost daily.
We're getting them. They're coming on board with the centralized endpoint detection and response. So there is improvement going on within K-12. So progress is being made. And that, like I said earlier, I think there's two more years of SLCGP grant money, and that money will go into the counties and cities. They have a plan for how they want to spend that money, respectively.
So improvements are being made. On your previous question, so my focus, and I may get Jay to help me with this answer, so right now the focus is on the executive branch, but my thoughts are if we build and we develop good cyber programs at the executive branch,
You know, constitutional offices, judicial offices, they can fold into those plans whenever appropriate, right? But if we get good governance and good consolidation and good cyber services and standards in place, it will be relatively easy to roll in, you know, the constitutional and judicial offices.
Speaker 115
1:10:43
Okay, so, and that does answer my question. So those
Representative Andrew Collins
Unverified
1:10:48
are not part of the things that are being offered, really not part of your purview.
How about legislative? Same thing. Like, as far as, you know, our operations over here, those are just operated separately without necessarily buying. It would have to be later optional buying into this if we wanted to. Yes, I believe that would be the correct
Gary Vance
Unverified
1:11:08
answer. Okay. Thank you. Representative Richardson. Thank you, Mr.
Speaker 64
1:11:17
Chair. And if I understand correctly, we'll have to do some legislation to make that work for you guys to have the ability to oversee other areas.
But I did want to back up and just touch on one thing. You talked a lot about tools, tools, and endpoints monitoring. I'm making the assumption that this is also going not just the endpoints, but you're also hitting the networks and the environment and doing active threat searches for those in those spaces as well. Okay. Other than that, what else do
Speaker 111
1:11:53
you need? Well, I mean, I feel like we're making great progress.
Gary Vance
Unverified
1:11:59
We, you know, we're doing, we're working on a skills assessment with the idea that we can leverage resources that we already have today so that, you know, it's not a matter of having to go out necessarily and buy new tools, although we are doing that in some cases, but we also think that we can generate efficiencies and some effectiveness through what I call shadow IT or shadow cyber tools.
And we already know we have some of those out there, and we've developed early targets for where we know a standard tool may eliminate multiple tools. So, I mean, I think it's just the continued support that you're giving us today that's been so helpful. I mean, the legislation to centralize and consolidate was a really big step for us because up until now, I had no purview from a cyber perspective over any other department other than OST.
So what's been helpful now is we've got the backing and we've got the support that we need down to the department level, which has been huge. But I think going forward, just having the support that we've already seen that you guys have already given us, I think is tremendous. And if we could build on that going forward, that
Representative Stephen Meeks
Unverified
1:13:38
would be fantastic. Okay. Thank you. And colleagues, a lot of times with
technology, it's generally out of sight, out of mind until the bad guys get through.
And I just want to let everyone know, and I don't want to get into any specifics here, but under the current law, whenever there's a major cyber breach, legislative leadership has to be notified to make sure that we're all on the same page. And it's not unusual for once or twice a year for us to get those notifications. So this is an ongoing concern. You guys are doing a wonderful job of trying to whittle that down to zero and appreciate the work that you're doing on behalf of the state. So I guess last but not least, everyone's favorite topic, artificial intelligence. So Mr. Magoo, if you'll take it away.
Speaker 90
1:14:24
All right. Thank you. And as one preface to this, I did give everyone a copy of the initial report of the Arkansas AI and Analytics Center of Excellence. One thing that's changed in that, it makes some references to the data and transparency panel. But we had some recent legislation with Act 375 of 2025 that sort of matured the data and transparency panel into a network of data stewards. The DTP was really about setting the initial strategy and really working out secure governed data sharing integration and use across the state.
That's really moving into a more operational phase. We have a longitudinal data system. We have a statewide data hub. We have standardized data sharing agreements and all these things. And so instead of meeting for 90 minutes quarterly to talk strategy, we're really kind of moving into a more operational network. So under that Act 375, each department will name at least one data steward, but it can be more because it can be per department, per division, per program, whatever makes sense at the time for the department.
But those data stewards are responsible for operationally cataloging the data, very much like the hardware and software that Jay talked about. And then, you know, as we'll see, we'll kind of probably lean on that and do a similar type
Speaker 86
1:15:52
of thing with AI. And for executing the data sharing process.
Speaker 90
1:15:57
The origin of the data transparency panel and the data hub and all this started with Act 12A to 2015, which really sought to eliminate duplication of data and effort.
So that's all part of making sure that everything's cataloged, so RAN knows where everything is, so we don't have duplicate efforts. So if there is a data need by a program or service, that that department can find that data wherever it lives in the state and have a secure, governed way to reach out, get the approvals, share it, and so we can eliminate some of that duplication data and effort. Moving on to artificial intelligence, we're going to get an update on the AI-COE.
I'm going to hit a few of the highlights of the initial report and what's happened since then, so we can kind of get into some questions. So the goals of the CIA, we distilled those down at the beginning to protect Arkansans and their data, to improve government services, and to prepare Arkansas for the AI economy. representatives from multiple agencies at the house and senate there are a couple of members on this committee higher education at the business community that the chief
workforce officer really giving us sort of a diverse set of perspectives our methodology for kind of studying this kind of started broad and got specific we did a wide literature review we looked at the task force reports from other states and every you know comment let uh we found that from the national council state legislatures they had a a database of about 1600 different pieces of ai related legislation and looked at executive orders and just really just tried to kind of figure out from the states who have already been looking at this some since 2019
what have they already done so we don't reinvent the wheel um then to kind of pull it in to um to arkansas we really looked at arkansas's priorities um we we broadened out the the group um a few months ago we had ai roundtable that where we had all of the departments and we had about 75 participants really have an all-day event talking about um a speaker on the national perspective on ai kind of the state landscape and then kind of drilling deeply into more education
workforce and healthcare aspects and so we're kind of continuing to um to focus in because it's such a broad and dynamic topic um as far as moving from that sort of initial study to the more operational governance aspect we started with the guardrails they're on page five of that report these are intentionally meant to be very enduring because we know that um we're deploying ai technologies today that didn't exist a year ago so these need to be very plain language not bound
to specific technologies just very clear common sense you can read it and decide whether it is me in that guardrail or not the next step was starting to implement those guardrails and that really comes down to governance which starts with people in process so after we develop the the set out the first report and we've used our subsequent meetings really starting to iteratively develop and refine an AI governance process so we developed a set of draft policies around privacy
transparency explainability human oversight all these kind of key topics in the guardrails and started developing an AI inventory and so kind of point forward as a department had an interest in deploying an AI technology or maybe it was something that came up for renewal. They already had it in, but we're starting to run it through the governance process. We would kind of work with them, kind of assess the risk using the AI risk management framework from the National Institute of Standards and Technologies
and kind of learn from that. But, you know, what's going well? What are best practices we can replicate? What are risks? and try to streamline that process, make it as efficient as possible, and now we've kind of moved it over under the TIG process that Jay talked about. Through that, we kind of learned by doing. We've had a couple of different pilot projects we've kind of learned there, and now we've recently did inventory across all 15 departments of AI that's in use
or that they plan to use. And then going forward, this will just be part of the natural TIG process under IT governance. So we'll have IT governance, cybersecurity governance, data governance, AI governance, you know, all interrelated because they all impact each other. Next was having secure and efficient AI infrastructure. and actually we talked about the data hub gives us a strong strategic advantage there as a state
because the AI is only as good as the data from which it's being fed. So we kind of recommend leveraging the data hub, leveraging the data governance controls that are there and extending it for AI governance and just naturally extending that environment as needed to harness the capabilities of AI safely to deliver better citizen experience, you know, efficiencies where we can find them.
And then capacity building, we've got our governance, we have our safe environment in which to harness AI, but, you know, people need to know how to use it. So page six has a four-tier framework where we've kind of said, you know, we've got executive AI training. There needs to be some high-level understanding, and we've done, back in January, February, during session, we did an AI executive briefing for some of the legislators.
But we know that, you know, we probably need high-level sort of AI literacy for departmental leadership and state leadership. We need the AI training for just general state employees. I think that goes along with cybersecurity training, making sure people know where it's safe to use AI, where there are going to be impacts, making sure people know what data is safe to put in what environment and for what purpose. The deeper technical training for those state employees who are actually implementing and maintaining these systems,
and then the more professional training for just the roles that are being impacted by, and that's changing the processes. Lastly, looking at a different part under our purview is the state longitudinal data system and the economic security report, which is consumer information used by every 7th to 12th grader, every incoming college freshman, other adult learners for their career exploration and planning,
we realized that we need better information on how IAI is changing labor market demand so they can make informed decisions. So we've got some efforts underway to improve our data collection and reporting on the labor market impacts of artificial intelligence. So we've kind of walked through all that. We're pulling together and disseminating our next set of recommendations now, and I think we'll continue to have some pilots and just really operationalize this
Speaker 86
1:24:00
under the TIDG process and the overarching IT governance.
Representative Stephen Meeks
Unverified
1:24:07
Okay. Thank you, gentlemen, for your presentation. So definitely off to
a good start here. This past summer, I had a chance to attend AI4, and I don't know if you're familiar with that or not, but AI4 is the largest artificial intelligence conference held annually in North America. There were 8,000 people from like 50 different countries. I was one of only three
state representatives that was there. And I was actually asked to speak on one of the panels. And And so I was in a room full of about 300 AI businesses to give this presentation. And one of the things that I told them was is they're generally, you know, they like to focus on the big states, you know, the Florida, the Texas, the California is where a lot of these resources come from. And I encourage them to look at the smaller states like Arkansas.
I said Arkansas a lot for hopefully obvious reasons. Because I think one of the benefits that we have as a smaller state is we can be a lot more flexible and nimble in this space. This is as you, I think everybody in this room realizes AI is going to be a transformative technology. And the first state that can figure this out and do it right is going to get a huge advantage over our sister states. That's economically, education, all the way up and down the line.
And so as we're moving forward on this, I think our state has the potential, because we're smaller and can be more nimble, we have the opportunity here to be a leader in this space. One of the presenters, and this is a business owner, One of the things that he had done in order to help get his employees trained up, because I think, you know, and I changed the law to require AI technology use policies across the state.
But at the same time, my concern is, is that if we do from a top down, we're limiting our opportunity to take advantage of this. What several of the businesses said that they did was they created opportunities for state employees. They gave them, say, an hour or a week, two hours a week, and set up a sandbox and let the employees just play with the technology for an hour or two a week.
No strings attached. Do what you want. Learn the technology. And he said that once he did that, his employees figured out how to use that technology, implemented into their workflow, and now his business, the employees were able to use AI and complete within an hour what used to take weeks to get done. And obviously that created a huge, huge advantage for his company.
And I would love to see us as a state implement a similar strategy because, you know, like with the cybersecurity, if we say, hey, come take this class, there will be some people that do it, right? But then they take the class, what happens? If the average state employee is learning how to use this, not only does it, it gives them a skill to better prepare them for the future, but because they're the ones doing the job day in, day out, they would be much better equipped to figure out how can I implement this to make my job better?
How do I use this tool, right? Us here up at this level, we can't, we can't come up with all those thousands of use cases out there. And so how do we unleash our state employees to have that opportunity to do that? And so that's the challenge I'm going to put out to you and to, you know, Department of, you know, Transformation and Shared Services. How do we create the opportunities for our state employees, the average person who's, you know, taking the phone calls, doing the evaluations?
How do we allow them to unleash this technology for their jobs? Obviously, we've got to have the guardrails in place. You guys have already worked on that according to the report. But I would like to see us really jump on this because if we don't as a state and we come in last, none of us up here want to see Arkansas in 41st place or 45th place when it comes to this technology. We want to be in the top ten.
And in order to do that, I think the way that we need to go about doing this is giving these tools with the proper safeguards in place to all of our state employees, learn this technology, learn how to use it for your job. Once you kind of figure out a use case, bring it to your supervisors and let's see what we can do to implement it. I don't know if you have any thoughts on that. How do we go about implementing it? But I would love to hear your feedback on it. Now, I will say, after I predicated that,
Everybody at that conference, business, government, and again, these are from 50 different countries as well, the prevailing thought was we all need to do this, and everybody thinks they're behind. And so there's a sense of urgency here, but at the same time, I want to be smart. I want to take advantage of this to make sure that we become a national leader on this.
I want other states to be looking at Arkansas to figure out how to do this. So I would love
Speaker 86
1:30:05
to hear your feedback on this. And I completely agree. And so far we're not last. Code for America's put our report in a
Speaker 90
1:30:12
dashboard and everything that a lot of people are looking at. And it has four stages and are already up to the second, the developing stage. There's a good number of states still in that first stage, and I think pretty soon we'll be moving. There's only three states in that top stage right now.
I think it's California, New Jersey, and Pennsylvania, and we're working our way up to that third stage. And we've spent a lot of time looking at America's AI Action Plan, which really talks about the need to move quickly, rapid adoption of AI at scale, And the key barriers to that are you have to have a literate workforce and people have to trust in that. And so, you know, I think the governance, the secure infrastructure, you know, literacy, these are all some of the key ingredients to having the trust so that we can move fast and realize the advantages.
Representative Stephen Meeks
Unverified
1:31:03
Right, yeah, because the last thing I want to happen is you all have to work up all this and then it's stop, right? We've got to get this out to the state, city. i mean my count folks in the county are asking me hey how do we implement this at the county level right and so um obviously a sense of urgency here uh representative richards
Speaker 107
1:31:26
uh you're up sir thank you mr chair if i didn't ask a question it would
Speaker 64
1:31:31
be odd right so uh yeah um question for you have you started receiving uh requests for ai tools specific tools to do specific jobs like
traffic engineering or what have you. I know that there are a lot of AI-based tools that are starting to come to market at this point, and I'm wondering if you're seeing requests for those types of tools from the state government, if you've started compiling lists or determine how you're going to go about implementation, what kinds of processes you're going to
Speaker 90
1:32:00
go through for review, any of that kind of stuff. Yes, and that's the AI use case inventory, and now it's part of the TIG process. So the Titch process is whenever somebody wants to make a purchase or procurement,
but also if they're just doing an information technology project. So in many cases, AI capabilities are emerging in tools that have previously been procured. So it doesn't necessarily have to have a cost associated with it. So we kind of drew that line with production deployment of AI. But we've seen a lot of early things around document, summarization, query, a lot of things to help with legal documents,
a lot of improvements over OCR to scanned text translation. So, generative AI tools. Yeah, a lot of generative. There's been a fairly broad variety. Not
Speaker 86
1:33:02
the specific ones you looked at. Well, I'm just going from my own experience. So obviously
Speaker 64
1:33:10
I'm sure there are AI tools coming around for a lot of the day-to-day tasks
and providing oversight and review, and I'm just curious how much of that we're actually seeing. And most of the time we're going to get that from what Representative Meek, our chair, was speaking to, is that's coming at the lower level. They're seeing this or that, and they go to a conference, and this tool is coming up. And just, you know, how are we managing those? How are we discussing those as we're coming through the standard procurement process? And they get the standard reviews associated with everything else. Do we actually have the policy for AI use pass through the various departments at this point?
Or we're still working to develop that? I guess that was part of that discussion, but I didn't really get. I know you have some points of the policy that you're bringing
Speaker 90
1:34:04
together. But do we actually have an AI use policy that's in place? The full acceptable use policy is not currently published. I think it's pretty close. But we've been developing it, testing out of real-world reviews through the AICOE, giving provisional approvals.
I think we're probably getting close to the point where we can formalize that and kind of put it in place
Speaker 66
1:34:29
through the data. So if you don't mind, what's the process for approving a tool
Speaker 90
1:34:35
that has an embedded AI functionality if we don't have a policy. And we're largely kind of aligned with the NIST AI risk management framework. So depending on the nature, we might start with asking them some questions initially about, okay, what type of data is involved?
What's the sensitivity? Is this for resident-facing? Is this staff-facing? What's the impact? if a decision is made that's erroneous, things like that, to kind of understand the risk that's placed within that risk management framework and then what sort of controls are in place to mitigate those risks. And then if it was a particularly interesting one, you know, either in a scale and kind of bring that to our get on the agenda at the AI COE meeting
so we could really kind of take a more in-depth look and have a lot of discussions and kind of run it against these policies to see, with these specific examples, will these policies work in practice when we're really starting to see lots and lots of these. And we've really been seeing an uptick over the past, really about the past 90 days. There's been a marked uptick in the interest in deploying these technologies, but we're also seeing common patterns. Hopefully, both from a technology procurement standpoint, like Jay was talking about, economy to scale, kind of using shared services and getting some consistencies there.
We'll also kind of hopefully have some cross-pollination of best practices around similar use cases. Yeah, and of course, from my seat, I
Speaker 64
1:36:12
have a lot of concerns. It reminds me a lot of when Microsoft started producing Access, right, Microsoft Access. And you had all of these businesses going, these are great, and then they would build this little bitty piece that would do this little bitty thing, and then somebody said, hey, that's cool, let me use it, and the next thing you know, it's a business-dependent kind of function that's spread out all over the place, and it's hard to get rid of, and
not built for that. So I see the same kinds of things with a lot of the AI tools. It's a little bitty thing that does this, and the next thing you know, 15 people have adopted it, and now you've got this sprawl and the challenges associated with managing that. so anyway I appreciate the answers good luck with implementing the
Speaker 90
1:36:56
policy it's gonna be fun on that last point there's a Center for Public Sector AI that 26 states are participating in that kind of gets us together and with you know digital response office management budget and others and a director I want
me was letting us know that you know we have an opportunity here because unlike the way IT is kind of unfolded in the past we all you know we have a chance to do this all at once. So this is our best chance right now to really kind of get ahead of some of that sprawl and mix and wise decisions on the
Representative Stephen Meeks
Unverified
1:37:32
front end. I think that's why we're really being particular about the governance. I noticed one of the recommendations you have in here is that we need to maybe see about um creating a position for a chief ai officer um so obviously your
main focus has been data and data governance um so can you kind of talk to us about the need for that role versus what your role is i mean it seems like kind of like you're doing a dual role right now but do we still need to get an ai person and what does that position look like Is that going to require legislative action in order to create that role? And what would you see a person in that role doing? So can you kind of flesh that recommendation out for us?
Speaker 86
1:38:17
And I can speak to the need and then Jay about the mechanics. But as far as
Speaker 90
1:38:24
the need, I think they're essentially, they're both very full-time jobs. There's a lot going on with both data and AI. And they're related, but they both require a lot of focus, especially when you're really spread across 50 different departments and all the different things going on right now with data-related HR1 implementation and AI is evolving, and it's quite a bit.
So I'd definitely say that it requires at least two people to cover all of that if we want to kind of take a national leadership stance. Yeah, I mean, we would
Speaker 85
1:39:03
just come to personnel committee and ask for that position. Office of State Technology probably already has a position that we can just change the title on. Okay,
Representative Stephen Meeks
Unverified
1:39:12
so is that something that you're looking to pursue in the near term or is that just an option or kind of where you're thinking on what we want
Speaker 85
1:39:21
to do with that? I would probably say at least probably first quarter of 2026,
Representative Stephen Meeks
Unverified
1:39:26
not sooner okay all right excellent okay all right colleagues any other questions i know if we've covered a lot today and so yeah it's a lot a lot to get our minds around okay all right well seeing none gentlemen thank you for being here and for sharing with us the work the very important work that you're doing for the citizens of our state and we look forward to more updates in the future all right colleagues again i appreciate y'all hanging with us for all this a lot of important discussions today, seeing
nothing else on the agenda. We are adjourned.
Agenda
A. Call to Order
B. Consideration to Approve the April 23, 2024, Meeting Minutes [Exhibit B]
C. Consideration of a Motion to Authorize Chairs to Approve Special Expenses Incurred by the Committee
D. Discussion of Cybersecurity [Exhibit D]
E. Discussion of the Arkansas AI and Analytics Center for Excellence (AI CoE)
F. Discussion of DeleteMe [Exhibit F]
G. Other Business
H. Adjournment
Documents
| Title | Type | Pages | Source |
|---|---|---|---|
| Agenda — ADVANCED COMMUNICATIONS AND INFORMATION TECHNOLOGY - JOINT, Oct 20, 2025 | Agenda | 1 | Official source ↗ |
| EXHIBIT B - Minutes 04-23-24 | Exhibit | 1 | Official source ↗ |
| EXHIBIT D - Discussion of Cybersecurity | Exhibit | 9 | Official source ↗ |
| EXHIBIT F - Discussion of DeleteMe | Exhibit | 14 | Official source ↗ |
| HANDOUT - AI-CoE-Initial-Report | Exhibit | 7 | Official source ↗ |
Speakers
Representative Stephen Meeks
Unverified
Taylor Tabner
Unverified
Speaker 11
Senator Breanne Davis
Unverified
Speaker 22
Representative Matt Brown
Unverified
Representative Andrew Collins
Unverified
Speaker 64
Speaker 66
Speaker 85
Speaker 86
Gary Vance
Unverified
Speaker 84
Speaker 28
Speaker 115
Speaker 111
Speaker 90
Speaker 107