Said in CommitteeBeta

Exactly as spoken.

Advanced Communications and Information Technology - Joint

October 20, 2025 ·1:30 PM ·Room A, MAC ·1:40:09
Video Transcript 5 documents

Transcript

Transcript available SliQ live captions ✓ Whisper ✓ Download .txt
Machine transcript

May contain errors. Verify important quotations against the official video.

About transcript accuracy
Source
SliQ live captions
Model
SliQ live ASR
Processing date
October 2, 2026
Representative Stephen Meeks Unverified 0:36
right colleagues I've got 130 so if everyone wants to kind of settle in we'll get kicked off here in just a minute. right everyone we're gonna go ahead and get started with the joint advanced communications committee meeting this is our first meeting of this session. I think this interim so appreciate everyone being here on a on a Monday. first thing we need to do in order to get started is to approve the minutes from the april 23 meeting. if I could have a motion for that ok we've got a motion second all in favor say aye. Any opposition we'll consider that approved next I need a motion to authorize the chairs to approve special expenses incurred by the committee during the interim if I can get a motion for that. OK, motion second all favor any your post? OK, we will consider that approved. All right colleagues we're gonna jump right on into this. we've got several important items we're going to discuss today related to technology as y'all know this is a very fast moving field. what I'm gonna do without objection, I'm gonna take item F out of order. we've got folks from deletee are on video and so instead of making her wait through all the other discussions, I'm gonna go ahead and let her go first. but so I first heard about this company back in February when I was at an NCSl conference and I'll let her get into the details of what they do but based upon that discussion and what's been going on in the world I felt it very important and timely for us to learn about what they do, why it's important and why we should consider this not only for the legislative body but all the other elected officials within the state government. So with that Miss uhtavenner, can you hear us OK? yes sir right so if you would just introduce yourself to the committee and the floor is all yours. Hi my name's
▶ Play Suggest a correction Report an error
Taylor Tabner Unverified 3:25
Taylortappner. I am with deletee and we are working to help protect legislators, state officials from threats
▶ Play Suggest a correction Report an error
Speaker 11 3:32
harassment things like that but from here I'd love to jump into a PowerPoint presentation if possible so I will go ahead and share my screen now. you guys let me know if you can see it. we've got it perfect. OK so
▶ Play Suggest a correction Report an error
Senator Breanne Davis Unverified 3:48
realistically what I'm here to do today is really just to kind of help provide you guys with an additional level of protection because what we are seeing more than anything is that exposed data is creating real world risk. you guys are not immune to that probably a little bit more susceptible. so what I'm hoping to do today is just kind of show you what's out there how we can help and answer any questions that you guys may have. So little backstory about us just so we can kind of set the scene a little bit first and foremost kind of wanted to give you an introduction to delete me. We are a data privacy company. we actually work to remove personal information from data brokers from the open web so think things like google searches things like that but why this matters and why we're here today and why I represented meeks brought brought me on was because that 84% of state legislators really have reported being insulted, harassed or something within the past year or so on top of that kind of double clicking a little bit further it continues to get worse.44% of those,44% of your peers probably some of you guys in their room have been threatened. I mean that's not just you that's your family's and that's really where we kind of come into play what we see here is when we're talking about severity of threats you know and what I will say here more than anything is that it's not really a threat you know I think a threat implies that it may or may not happen. I think this is a true risk because what we do see more than anything is it's not a matter of if it's a matter of when and it really is a matter of to what extent I know there's been incidences in the state here I worked to kind of cover from delaware down to Florida and over around Oklahoma. I can't tell you a state that has n ' t had some sort of incident so we'll leave this here and you guys kind of review it at your leisure. I know you guys have this printout as well but this can vary. you know the severity of threats the the severity of risk is anywhere from true death threats to swatting to doxing to threats to your family to death in a lot of these scenarios you know if we think about the tragedy that happened in Minnesota not too long ago what we will see is that what ultimately is causing this is these data brokers it is the exposure of pII. so here what we're looking at this is the affidavit from everything that had happened in Minnesota. this is public record, this is not us pulling it this isn't confidential this is again public record. what you will see here though is these are all common data broker sites. These are all common peopleiner sites. So for you guys for other elected officials for judges for anybody really on the public sector side of things that is public accing in some regard this is even more damaging because these are as simple as you know, understanding and knowing somebody's first and last name in the state that they're located. Well for you all when you are representing the state of Arkansas that is public knowledge. so what I will do from here is I'm actually gonna switch over to a site called Familytreeow. This is just the simplest example of what I just outlined on the previous slide and show you how easy it
▶ Play Suggest a correction Report an error
Speaker 11 6:56
is to really find any of this information so bear with me one second as I switch over one second here and so here
▶ Play Suggest a correction Report an error
Senator Breanne Davis Unverified 7:12
making sure we're looking at family tree now. this is that simple site right this is all public knowledge this is a free site so it's not behind a paywall we're not asking for any credit card information they are not either. I'm gonna show you my grandfather. he is a public or he's an elected official in Virginia as well or was a while ago but when we're thinking of peers thinking of similar exposures this is what you guys are working with. so again all you need first, last name and state for you all, everybody has all of that already. click searchch records we'll give it a second to load he is going to be this third one down right here we'll click the records we can click out of the ad so first and foremost he knows I'm showing this he actually wants to use this as an educational touch point really to kind of help just spread the word. So for you when we're thinking of you know you have constituents you have somebody that doesn't like the bill that's being proposed doesn't necessarily like some of the support whatever first things that we see here the first thing that pops up is your home address. this is a hyperlink . this takes you to a google map, helpps individuals find exactly where you are so when we're thinking of incidences even as simple as a swatting standpoint, right? they know where to send them. they know where to have these calls routed but when we think of a little bit further and a little bit broader think of like a Daniel's all situation or the situation in Minnesota. we have people showing up and what we see on top of this as we're working with a lot of you know FBI agents or as we're working with quite a few to talk about you know mitigating some of this risk. what we see is we see individuals we see the bad guys take this information and they idealize the attack. so they're looking at the layout of your home where you and your family are sitting for dinner, what have you all of that starts with a simple exposure of pII. go down a little bit further. got your phone numbers this could be
▶ Play Suggest a correction Report an error
Speaker 22 9:08
a variation of be cellphone number could be your phone number at home if you still have one in some scenarios it could be your work number what have you it's all right here now what I would
▶ Play Suggest a correction Report an error
Senator Breanne Davis Unverified 9:20
love to double click on here which I think is even more important not that it's more important than you but equally as important this is all of your family members information. so this could be your spouse's name. This could be your kid's name specifically if they're over 18. and everything that we just saw for you we'll see for them as well. Now one thing that we hear often specifically when we're working with public servants and elected officials is that you guys signed up for this you know when you guys have a duty some regards I I agree with that right? like but you didn't sign up for this and neither did your family you know and so we're not looking just to help you protect yourself but those closest to you because again two data points which is public knowledge there is an ample amount of exposure there. I'm gonna stop there and I'm gonna kind of piggyback go back to the previous slide that we were just looking at and we'll answer any questions in the next little bit.
▶ Play Suggest a correction Report an error
Representative Stephen Meeks Unverified 10:21
and while she's doing that colleagues if any of you have your laptops with you, I would encourage you to go to that familymiree now website.y in your name and you can see all the information that's out there publicly available about you and your family so back to you Perfect. no thank you for that and what you guys can do too
▶ Play Suggest a correction Report an error
Speaker 22 10:39
I think you have the printout that is the QR code you guys are welcome to look there also happy to
▶ Play Suggest a correction Report an error
Senator Breanne Davis Unverified 10:44
send out whatever you guys may need just so you can search that but the best way to protect yourself is to know what's out there to start so I would 100% recommend starting here. This is the simplest way to find out what's out there.nother great way is to do a quick, you know an easy Google search you'll see all of those populations at Ggemini is great as well because what it's doing is collecting any of these touchpoints that are out there for you and putting it in one centralized location but you know I think the the starting point for you all in this scenario is is knowing what's out there so then we can then look at preventative and proactive solutions to help remove it. Not gonna spend a ton of time of on this slide but what did you just want to call out that you guys you know aren't the only ones looking at this we do have a footprint in over30 states specifically on the public sector side of things. we actually have some in the state already in Arkansas we're working to protect the judiciary there but looking a little bit broader there's coverage nationwide constantly changing all of this to say like this is a public sector solution it is more important now than ever not gonna get super in the weeds of this but do just want to kind of talk through how this approach works realistically what we do so we've talked about the lete mehaile it's a data privacy company what have you but the long and the short is that we actually go and we work to remove all of your exposed personal information from the openweb. how we do it couple different ways but realistically we do it to ensure that we are protecting you so there's a lot of automation we do it so we can keep up with these changes at at scale because one thing that we know is like we're constantly exposing ourselves right? like we're in the age of technology we're all using our phone we're doing a doorash if we're working late in the office where the convenience of an amazon to send stuff home whatever especially during busy seasons during sessions where we're all you guys in particular are working late to get things across the finish line. We understand that we're exposing ourselves. so how we do this is we leverage our automation to go and scrape find any potential matches for you all. then we have a team that actually goes through and fact checks it. The importance of that is we want to make sure that we're protecting the right people. you know because if we even go back to the previous example that I showed of my grandfather, right? There's multiple different variations. it's a probability thing at this point it's highly likely that somebody has the same name as you somewhere in the world we want to ensure that we're protecting the right people right if we're protecting a senator Jones but it's not the right one who are we protecting? what have you those sort of situations that was just an example especially with the common names we need to make sure we're doing our own due diligence so in this process there's automation there's a human component going through going through this process of actually ensuring that we are removing the right information for you and ensuring that it stays down. the other thing to double click on there is that we have the process fine tuned but what we see a lot of times too as this is as if legislation changes or what have you there's a reporting component that needs to be included as well you guys will have access to that it's in your own privacy advising center it's also one of these things that will be sent to you guys can know more and do better again one of these things the more you know the better you can protect yourself. We won't get into the platform in the partnership today but happy to double click on that in a later date if needed. these are just some quick examples of before and afters of what you could would expect there's just kind of double clicks on what we looked at previously so this is a very very common people site this is radari 99% of people are going to be on here on the left is what you would see prior to a service or prior prior to you know anything from a data removal standpoint you're gonna see it out there you're gonna see all of it out there after the fact you're just going to see a lot of this gone same thing here when you're looking at searches on google again going back to kind of understanding what's out there. Most everything is out there 9 times out of 10 if you have a constituent that's angry or you know somebody that's looking to potentially harm you and your family they're going to a google before they go to a tax recordsite before they go to a data broker they're going to google first. so why this is important here and not even really to get into the weeds of this but there is a component with the delete meat where we actually go and we clear out the google cache, meaning that we're not leaving any breadcrumbs you know so you guys truly will have a pretty clear digital footprint and it is constant right?gain we're constantly exposing ourselves but we are constantly working to protect you all so you guys can keep doing the good work that you guys are doing for the citizens of Arkansas. Super super important feature here specifically for those on the legislative side of things this is something we also to all elected officials were doing a lot of it with the judges already we can obviously continue to do more of this at scale we'll do real estate listing removals so think of a zillow, think of a realtor.com because again because our public servants but you don't need to bring that home and you don't need to bring these people inside of your home. So protecting you guys in a way that allows you to continue to do your job but does put up some boundaries and some parameters in place for you and your family. Same thing here with this s street masking view essentially working with Google Maps to blur out your home, making it a little bit more secure again allows you to not go from side to side see the interior, see the exterior, understand the angles, what have you this is just an additional way in which we are working to help protect you and your peers. now we'll stay here for a second because there's a couple of different things to talk through here. so realistically my goal for this conversation is just to really provide you guys with more solutions to help protect yourself. One we have the tool which is super effective really important. The other thing that we have done is we've actually worked to help draft legislation so we've seen this in Utah it allows us to really kind of remove all of this information for all elected officials all public servants there so what I will say here is when we're talking about this there's a couple of different layers right? The tool itself I would say is a short term solution. the legislation is a longer play but we were built to support it and we can also help support it in other ways but the benefit of this and what I will double click and say here is that we are helping to protect you guys and your peers but also broader think judiciary think state agencies like family and child protective services department of laborbor Health and Human Services right now the footprint is vast because we see that the climate and the landscape continued to shift based off of severity of threats and we can help with that again tool and legislation wise. not going to really harp on this but when we think of how we can help you know the biggest thing I will say above everything is that we want to reduce your risk and this is something that I think we all can agree on is the risk is out there. how do we protect yourselves? how do we protect your family and these changing kind of climates like what does that look like? and then secondarily too I know there is a it's cyber m cybersecurity component obviously a technological component. what we see on top of the physical and just the digital protection that we see on an individual level is that network security for organizations that partner with us or that we have helped really see significant drop in fishing attacks because the majority of the time the true metric is 9x out of 10 It starts with a fishing a targeted fishing attack from a cybersecurity data breach standpoint which starts from exposed pII. cut the source protect things long term but that's all I really have. I really appreciate it. I'm opening I will open up to any questions if you guys have anything. thank you colleagues a
▶ Play Suggest a correction Report an error
Representative Stephen Meeks Unverified 18:43
lot of times these these you know we we've seen judges that have been assassinated we had of course had colleagues in Minnesota that were assassinated within the last year and a lot of those began with searches of this online information. I think one of the stories and and you may know the details of this better where when the perpetrator went to assassinate the elected official the son or the daughter was with them and you know the story I'm talking about do yes sir yeah that's Daniel's laww. Yeah why don't you go ahead and tell that story. you can probably tell it better than I can. so I actually
▶ Play Suggest a correction Report an error
Senator Breanne Davis Unverified 19:22
had the pleasure of of meeting with Judge Salis a couple months ago and hearing her story firsthand and it was one of the most moving kind of scenarios that I've heard right like it's been several years ago and she can still kind of she still gets choked up but essentially what it was it was right around COVID herr son Daniel, I mean even myself were all guilty of it uses UberEats quite often and was having deliveries home and things like that well there was actually it was an angry prosecutor that didn't like the ruling that she had made.ound their information by a quick google search actually Famiree now which we just looked at found their information showed up at their house , shot her son Daniel point blank, killed him, and then shot her husband as well. Fortunately he survived but rocked their world justifiably so and so that was probably one of the first times that we have seen a lot of that really kind of really pinpoint the need and the risk for protections for exposed pII since then and as a result of that there is the federal the federal juris or federal judicial legislation that's Daniel's law that works to protect all of the federal judges there we're seeing a lot of that rolled out at state level as well but also like similar incidences in Minnesota I can think of the exact same situations in a Maryland quite a few other states like that's probably one of the most common ones but it unfortunately happens all of the time so the more proactive and preventative we can be the better it is.
▶ Play Suggest a correction Report an error
Representative Stephen Meeks Unverified 20:52
thank you and again colleagues this is not about limiting public access to us it's just making sure that the data that we have out there is not going to put us in a situation where we could become the the victims of some of these crimes. but that does anybody have any questions
▶ Play Suggest a correction Report an error
Speaker 46 21:16
uhpresentative Brown do you have the hit
▶ Play Suggest a correction Report an error
Representative Stephen Meeks Unverified 21:24
your hit your button again it's not shown up up here for me to there we go all right
▶ Play Suggest a correction Report an error
Representative Matt Brown Unverified 21:32
thank you very much for your presentation when you were speaking I I pulled up a couple of websites and there was nothing on the first one and I thought oh well myidd theft protection is working then I checked it on another site and my name did not come up but my deceased husband's name and address, which is my address came up and that's very concerning and that probably some of the names of his children also were there I don't I didn't look that deeply but anyway so would your service look for spouse's names and children's names and things like that ma'am so included in the coverage for yourself
▶ Play Suggest a correction Report an error
Senator Breanne Davis Unverified 22:20
specifically on the legislative side of things we protect your family members as well. so it's not just you it is next of kin because what we understand as well is like why all there may be some gaps in coverage or while you may have you know just some initial searches that aren't showing up for you or what have you. we understand that the connective tissue is just as exposing right so like in reference to the relationships that you just brought up like what we see too specifically from a risk standpoint is that if you guys are clean typically they'll go to the next connective tissue so a lot of times it you know like you guys are safe protected that information's gone they'll go to the spouse because that's the next way to reach you. same thing with the home address that you're still living at. so the short answer is yes ma'am. we will work to remove that information as well and there is no limit so what we will do is like typically it includes spousal coverage that can be there's some variability in that but we also want you to provide like hey like these are the connective tissues this is my mom, dad, brother whatever we'll work to kind of cut those ties and ensure that you are protected from that exposure as well. thank you yes ma'am. OK. representative Collins you're
▶ Play Suggest a correction Report an error
Speaker 54 23:29
next thank you and I actually use
▶ Play Suggest a correction Report an error
Representative Andrew Collins Unverified 23:32
the service personally so I I mean I definitely see the value of it the reason I did it was just kind of to reduce the amount of information that was out there I I kind of felt and recognized that there's no way to really get rid of something you know my data is gonna be out there in some way at some point it's a game of wackck amo that we will lose but I I would think that's even more true for a public official where there's even more information and if there's a situation where somebody is really trying to get that information I would think that they're going to be able to get it and so I guess I'd like to know your response to how your service offers protection given the reality that if somebody is targeting a specific person there's probably going to be a way to get a lot of the information that you guys are reducing the overall like instances where it's out there and I appreciate that but not really you can't really scrub most of that. I mean it's on public records and other things that you you guys can't even get to. sure yeah I think there's two answers to that and 2s
▶ Play Suggest a correction Report an error
Taylor Tabner Unverified 24:40
solutions so I'll answer it in two different ways. So one specifically for you all and
▶ Play Suggest a correction Report an error
Senator Breanne Davis Unverified 24:44
in comparison to the consumer plane that it sounds like you may already havepec specifically on the public sector side we also leverage humans so we have the automation we have the the automated opt outs which kind of gets some of that low hanging fruit it's pretty similar to what you have in the consumer side but on the public sector side of things so thinking of judges, thinking of you guys we leverage a dedicated privacy advisor so they're going to the hard to reach data brokers they're going to these hard to remove from sites and actually actioning on your behalf. so in that regards we see a significantly higher success rate but on top of that what that actually allows for is we have what we called an incident response sector of the public sector team meaning that you guys are never sitting in a queue and say you guys know that you're in session and you want to bump up protection you give us that heads up and we go and we go to those sites proactively even outside of our typical realm and we go and we work to remove that on your behalf to ensure that we have as much of a proactive response as possible and as much of a preventative response right? because to your point like if somebody wants to get you to or get to you they're gonna try they're gonna try all of these measures they're gonna do all of these things but the cleaner we have that footprint the better it's going to be and what we can do on the public sector side of things that we've seen significant improvement on especially when looking at a consumer side is that proactive threat response and that incident response so that's one but in regards to tax records and some of those government sites and what have you so without legislation you are correct we typically we can submit it as a custom request which also is kind of an added feature of the public sector side of things and we do see a lot of I would say wiggle room there but that's not a guarantee legislation is the long term play so this is the short term preventative play making sure we have your footprint as clean as possible legislation is what really really sets those parameters in the long run. OK, thank you. do you have a copy of that model legislation you
▶ Play Suggest a correction Report an error
Representative Stephen Meeks Unverified 26:53
can maybe email to us and we can make it available to the committee members OK perfect uhpresentative Richardson you're next. thank you
▶ Play Suggest a correction Report an error
Scott Richardson Unverified 27:04
Mr Chair. thanks for presenting this. it's interesting information one of the things that I experienced in my professional life is a challenge associated with darkk web entries or that data sitting in those locations that are unavailable continuing to repopulate and bring that data back to the fore end where it's easily accessible from from a consumer perspective. I'm curious if if your tool is if it's just a reactive associated with that or are you actually working with some of the back players like Waan or whoever to try to remove that data what is it what additional steps are you using from a from a dark web perspective so long and the
▶ Play Suggest a correction Report an error
Speaker 22 27:45
short there's again two approaches to this one typically we
▶ Play Suggest a correction Report an error
Senator Breanne Davis Unverified 27:48
focus on the open web specifically for individuals like yourself because what we see is in a lot of a lot of ways like if we're focusing on the dark web we're actually missing what's right out there in front of us. However, we do have partners that if that is sort of a necessity that prioritize everything on the darkk web for us and they're monitoring things like that where it gets a little bit dicey on the dark web is you actually can't truly remove it because what you would have to do is purchase batch data and sort of hope that your information is in there what we don't do we don't typically do that we do have partners that do it but what we try to do is really maximize our impact on the open web and leave that to the partner side of things if that's a must. thank you
▶ Play Suggest a correction Report an error
Representative Stephen Meeks Unverified 28:31
. Yes sir . Do you do you have any data or anecdotal stories that compares legislators who or states where your service is currently active or you've done the scrubbing and cleaning versus those who are exposed on the web I guess looked at the difference between those two groups to see have you noticed has there been any decline in the number of threats or harassment or just curious if you've noticed any difference kind of before and after yeah absolutely and I'm happy to share some of
▶ Play Suggest a correction Report an error
Taylor Tabner Unverified 29:10
those examples. I'm happy to send them over free to distribute if that's helpful but there's
▶ Play Suggest a correction Report an error
Senator Breanne Davis Unverified 29:15
a couple of different easy ones that sort of come to my mind and and I would say it's it's twofold so one specifically as I'm thinking out about a particular judiciary but you guys have very similar threats we actually have had the judges advocate on our behalf because of the lack of attacks lack of threats and how much that is done from a morale standpoint they actually use that as a justification to expand coverage in the state outside of the typical judiciary. so that's one that comes to mind but also when I'm thinking from like a cybersecurity standpoint and a framework standpoint and security posture within the state and the organization. there's one that comes to mind for me in the state of Utah where we were working with one of the IT individuals you know and he was the one responsible for escalating issues as they came in specifically on the personal side of things and one kind of data point that he gave me which I wasn't necessarily thinking but what as I kind of take a step back and think as an IT professional it makes sense he was saying you know the lack of or we've seen a significant decline in the number of threats that individuals have seen on a personal level. what we have seen though is we've seen we've been able to monitor our systems better. we've been able to isolate and pinpoint the attacks better so we're not seeing these incidences go beyond you know the capital or the courtrooms or anything like that we have those security parameters in place right? like you guys have systems in place that you guys were there where it gets a little bit broader is the second you step outside what's happening at home and those sort of things and so when we're thinking of that is it allows us to pinpoint and to kind of redirect some of the threats to the place where we have the security measures already there and we allow this to kind of work as an additional kind of expansion of those protections to your home to you guys on the personal level so it allows you to do things you know just with the cleanest peace of mind or clear peace of mind and you're not having to look over your shoulder as much so I'll send those over but several different use cases you know when we're looking at morale when we're looking at true threat risk when we're looking at things from a cybersecurity standpoint we have them and would love to share those data points with you. OK rightsome right Col any other questions
▶ Play Suggest a correction Report an error
Representative Stephen Meeks Unverified 31:35
all right Miss uhtavener, thank you for being with us today for presenting this information. obviously, this is a it's a growing concern there's a you know there's probably a lot of good people who could would consider running for office but don't because of this particular issue and so as we go forward into the future I wanted to let the committee know that a that this service is out there let everyone understand the risk that is out there by us not taking these proactive measures and for us as a legislature to considerly to strongly consider moving forward on something like this for ourselves and for the rest of the elected officials within the state so once again thank you for joining us this afternoon. thank you for having me and thank you guys for all the good work that you're
▶ Play Suggest a correction Report an error
Speaker 22 32:26
doing. really appreciate it thank you have a good afternoon all right
▶ Play Suggest a correction Report an error
Representative Stephen Meeks Unverified 32:30
colleagues we're gonna switch switch gears here now tell you what itemd and E is going to be related to cybersecurity and AI and I think y'all have a kind of a singular presentation. So if you gentlemen why don't you just come on up together instead of coming up one at a time and we'll let you get settled in there and then you can introduce yourselves to the committee and the brand new office of State Technology they're not coming on exactly these only thing happens the these things only happen at a technology committee meetings or where we have these technology issues yeah yeah
▶ Play Suggest a correction Report an error
Speaker 85 34:11
right yeah Jay Harton, director of officefice of state Technology and also the state chief information officer. good afternoon I'mRobert macggo
▶ Play Suggest a correction Report an error
Speaker 86 34:23
I'm the state chief data officer and chair of the AI Center of excellence. good afternoon my name is Gary Vance
▶ Play Suggest a correction Report an error
Gary Vance Unverified 34:30
I'm the state chief information security officer gentlemen all right thank y'all everybody for having
▶ Play Suggest a correction Report an error
Speaker 84 34:37
us here I think it was back in January of this year was the last time we kind of gave some updates we've had a lot of legislation passed thank y'all for that through the legislative body through this last session three key pieces of that legislation was Act480 which gave the office of statechnology IT governance over the executive branch and then also act489 which was the cybersecurity actct and then also Act375 which created the data stewards that each of the executive branch departments have to define to help with robert and his team's goals out of the I'll be talking about the Act480 and then Gary will talk on A489, the cybersecurity and thenRobert will be on act375 with AR data. so primarily out of the IT governance one of the main things that came out of that legislation was to give us oversight of all IT procurement within the executive branch departments so from that we created a process called the Technology and jetvestment justifications so any IT spend across the executive branch has to come before the office of state Technology for approval and review so what does that mean so that means that once they submit their procurement that they want to go through it goes through several what we consider gates within the office of state Technology so first it's reviewed by our enterprise architecture team to make sure that you know it's not some crazy one off service or something like that or also to see if we already have a service that's already offering that level of of offering of service to the constituents or to the other departments to make sure we're not being duplicative in services and we can also use that buying power from there it goes to Gary and his team for a cyber review cyber governance review and then so from his perspective they look at it to make sure that it's a secure solution that they're meeting all of the state security standards and then the next gate that it hits is uhRobert's team for a data management to make sure that if they are entering data into this that from our perspective we own that data and that if we get you know something happens with that vendor or whatever that we control that data and they don't own it at the end we want to make sure that we're protecting the state citizen's data in the state of Arkansas data so once it goes through all those gates then it comes to the office of state Technology leadership teamam for review and approval so that's where any procure IT procurement that's a million dollars or less if it is over a million dollars then it goes before an IT governance team and that IT governance team is made up of the secretary from department of finance Administration the secretary of inspector general umjessica Patterson who's the director of Office of state procurement and then myself and then we have a rotation basis of three CIs from each of the different departments right now they're serving a one year term on that so currently it's the department of humanman Services CIO department of commerce and department of laborbor and licensing. So those three CIOs sit on that and we meet every two weeks we don't want to slow down any procurement process so we're meeting every two weeks to get those through all the different gates so that we can you know move forward and not slow anything down also out of that became the approved hardware list so we're looking at the executive branch just like Walmart and Tyson and all these big corporations look from a procurement perspective so currently prior to this and and it's still ongoing we haven't can't do a full replacement endpoint so your laptops your desktops your monitors we're all over the place they were Lenovo they were HP they were Dell they were Aus all these different vendors and so what we've put out is an approved hardware list on our website that the departments can purchase directly off of and those don't they still go through theI process but it's a it's a quicker ted process or technology investment justification process because they're on this approved hardware list we do allow for exceptions there are some you know tablets or some your communications department's really like Apple products so they like the MacBooks and stuff for the graphics so we do have an exception process for getting things that are not necessarily on that approved list however looking holistically if you look at 22,000 roughly executive branch departments those exceptions are may be gonna be a5% maybe 10% at most so you're looking at spending you know with one vendor for those endpoints you're gonna drive that cost a lot cheaper than you know somebody making an agreement with HP this year and then somebody with Lenovo the next year so the next big thing that came out of the governance as well as the project management office so we're in the process of actually standing that up recently we just hired on a new project manager that's gonna lead that group so that ties into the technology investment justifications so we haven't well there's a couple of projects that have been submitted and approved through the technology investment justification process how those are out for RfP. so once those go into once therfP is awarded the department will have to assign a project manager specifically to that project but then they're gonna have to report back to us in our project management office to make sure that they're hitting their timelines their goals their procurement all that kind of stuff they're gonna have to report that up to us so that we're making sure that they're keeping on track and not you know a whole lot of change requests or anything like that so that we can start really making sure that the scope of these projects don't you know go off the rails and that all the timelines are being met and then the biggest thing out of the IT governance I think from my perspective at least is our service now implementation so Serviceow I called to IT people Service now is like SAP to the accountants and everything like that so it's a platform for IT people to be able to manage incidents problems all those type of things so when you're desktop or laptop doesn't work you can either call into the call center open aerviceNow incident you can email into the call center and it'll automatically open a ticket so that's that's kind of phase one of it the next phase that we're gonna have is that we'll have a complete inventory of all hardware within the executive branch not only just endpoints but umts switches network switches and everything like that so when we so when an entity goes to do an upgrade on a system they can say hey I'm gonna do an upgrade here and we can see what systems are impacted by that so that's gonna be the next big thing from ServiceNow we're in the middle of that RfP for implementation services so we're hoping we should have that before the AlC review committee hopefully in November now this one I think everybody from OST is really proud of from an IT assessment we finally as of last week, maybe the week before we actually have a full inventory reported by the departments of the applications that they are running within their department I think that's probably the first time we've had something like that since probably 2006 or 2007. we're of course going through that data and normalizing that data you know we have both ends of it where you know somebody reported that we're running4 versions of iTunes to where you know some person or one department just said we're running iunes which is is fine we have to normalize that data so now that we have all that data the next phase of the IT assessment is getting the infrastructure inventory so we're gonna work with the partner to go in and see what all server hardware what kind of storage and all that kind of stuff and look to determine the age of that equipment is it best to just let it age out in place move it to one of the state data centers or just migrate that into an existing service that the office of state Technology already has and so we're hope to have that completed by the first of the year and then follow up on that we'll start doing a IT skills assessment so as we start bringing these things into a centralized area we're office of state Technology are gonna need the assistance of these IT workers than the other departments to be able to help support these systems and applications so we're gonna work with the partner to do a skills assessment across all the executive branch IT workers to see what skill sets we have we know that there's quite a few that are retirement eligible not only from years of service but also age I think within the 130 office of state technology employees I think we're running about 20 that could retire today so we want to make sure that we're feeling back filling those positions and getting people up to speed so that they can you know move into those positions as those people retire out and then one other thing the last thing that I'll talk about is the consolidation plan so as we're gathering all this information we're working on putting together a consolidation plan so the office of state Technology already has roughly about 10 shared services that we offer to the other departments and so part of the consolidation plan is how do we bring those departments that aren't on our shared services on to that so that we're using one system a good example of that is enterprise backup so today some of the departments are doing their own enterprise backup at their location and then you know it may be replicated into the cloud it may be replicated into one of our data centers but the big thing is to get all of that centralized we're all using the same system so that if there is a disaster or ransomware event or something we can there's that knowledge and expertise that we can restore quickly and then the IT contract so as we start looking at these application inventories you know one that we've looked at real quick is adobe. Everybody's using adobe for pdf reader and that type of stuff so we're gonna look to work with Adobe to create a statewide enterprise contract so that we're sure that we're all getting the same pricing and the same level of service from adobe. So a lot of this was actually
▶ Play Suggest a correction Report an error
Representative Stephen Meeks Unverified 46:30
uhpresentative Richardson led the led the charge on this and I appreciate it because it's not there's a lot of good things going on in this space and obviously I know it's it's very early on in the process but it sounds like it's already starting to bear fruit for for the state so I appreciate that before we move on to the next part of the presentation does anybody have any questions regarding this aspect of it uhpresentative Richardson but it's turned on thank you Mr chairir surprisingly
▶ Play Suggest a correction Report an error
Scott Richardson Unverified 46:59
I I have questions so yeah so so you mentioned staffing as a bit of a concern 20 or so people that are going to be aging out I'm sure you have normal turnover just like everyone else are you have finding it difficult to backfill those positions is the current pay rate acceptable those kind of questions I'm curious about I will say this with the new pay
▶ Play Suggest a correction Report an error
Speaker 84 47:23
plan some of the positions that we've advertised we were seeing what I would consider record numbers of applicants so I haven't been doing any personal the personally any of the hiring or anything but the lower level managers within office of statechnology have said that they're getting a lot more qualified candidates excellent good
▶ Play Suggest a correction Report an error
Scott Richardson Unverified 47:46
you also mentioned backups and off and I'm kind of going to reverse order of my questions so and hopefully Mr Chair you'll you'll let me give me a little bit of latitude so yeah backups one of the big challenges that we've seen with ransomware is their ability to actually get in and delete what we call online backups right so I'm just curious in your plans as we kind of move forward are you looking at the ability to provide an offline iss that already a requirement air gaped backup
▶ Play Suggest a correction Report an error
Speaker 84 48:16
environment right so currently with the office of state Technology what we offer so we're doing disc to disk backup so we're doing that and then well probably the last four years we've still been spending that off to physical tape because they can't get to the physical tape so we've been doing that and that's one of the main reasons why we want to get everybody on this service is so that we have that air gap of you know so the ransomware people can't get to those tapes and delete the backups or encrypt them as well. OK thank you last
▶ Play Suggest a correction Report an error
Scott Richardson Unverified 48:51
question from me that the office of PMO so you mentioned that that's not up yet I know that's a big piece of bringing all this together and making sure that we can manage that making sure that we have a a published agenda if you will for an annual basis of what you're going to try to accomplish what types of projects are gonna be approved and whatnot when do you feel like that that's going to be coming online I mean so the office of state
▶ Play Suggest a correction Report an error
Speaker 84 49:18
Technology we internally had4 to5 project managers that just kind of handled internal stuff so they're we're transitioning those resources as well over to the the larger pMO I would probably say the first quarter of 2026 we'll have that in place the person that we just hired has it been working at axiom for a long time and so we're really happy to bring him in because he has a lot of experience not only from just IT projects but standing up project management office thank you very much and and
▶ Play Suggest a correction Report an error
Representative Stephen Meeks Unverified 50:00
and I know it's extremely early in this process but are you getting any kind of sense of what kind of savings if any that the state will realize, by pursuing these initiatives not not really yet we are seeing so the the
▶ Play Suggest a correction Report an error
Speaker 84 50:13
approved hardware list that we have out there that's like if dell is the preferred or is on that hard approved hardware list and with the just with the three months that we've had it out there we've already seen them that well let me back up real quick so that approved hardware list is if I went to dell and bought one, right? That's the that's the price that I get we've already seen with the volume that we're getting through Dell they've already come back to us and lowered that cost by50 dollars a unit so we are seeing some gains in that and I know like Department oforrections they have a fairly big procurement that's that's going through the technology investment justification to replace endpoints so we'll I'll be curious to see what that pricing comes back with but we're we're just not quite there yet. all right all right seeing no other questions we'll move on to the next phase.
▶ Play Suggest a correction Report an error
Representative Stephen Meeks Unverified 51:08
Thank you. good afternoon . So as Jay mentioned we've we've been we've been very
▶ Play Suggest a correction Report an error
Gary Vance Unverified 51:15
active and and we've got a lot of a lot of work going on and a lot of good work I wanted to focus on what we're doing in the cybersecurity area and in the two areas of the centralized cybersecurity office which is part of actct489 in the legislation and then some some executivele sober initiatives that we currently have in flight that are directly tied to Act489 as well so the first area I would start with is on our cyber policies we we to date have have been able to to centralize approximately 20 cybersecurity policies that have gone through a review and approval process and our and or are considered to be you know our approved state policies in those areas we've also identified roughly 200 cybersecurity controls that that we will use across the executive branch so we will standardize on those cyber controls which in and and in in a moment I'll tell you why those things are important as as we begin to develop a a standard baseline across all the executive branch where we're operating under a set of common policies and a set of common cybersecurity controls that that's that's gonna be very important for us going forward for the functional alignment that's also part part of the legislation as well so what what we've done to date on this is we've created what I call a virtual eso for each executive department that virtualiso will align with the state's cybersecurity office we will align those individuals with governance we will align those with standards as we get ready to implement standards across the departments they will be the go to person if you will out of my office into the into the departments and in addition to that we've identified roughly 20 to 25 cyber resources that exist today across the executive branch so we're going to work through the VSOs we're going to work directly with each individual department and we're gonna assess those skill sets and then we're gonna work to align those skill sets not only to perform the duties that they're currently responsible for in their department but also to align with state cybersecurity objectives in areas like threatat management compliance governance and and the policy work that we're doing as well so that will become our functional alignment as it's you know identified in in the legislation we have the visaos in place today and we're going to be conducting those meetings with those vSOs starting later this week going into next week and that should give us our functional alignment into the state cybersecurity office and that will be pivotal as we go forward then we'll have a a single centralized unit if you will of cyber professionals that we can really begin to then drop the governance you know down through their departments and the consolidation that we'll be working on once we get that function in place The next area are the the cyber initiatives that we're currently focused on that that we're considering a priority for what we're doing now and the first one of those is is is is centralized endpoint management detection and response so our goal there is that we will we will have advanced endpoint protection and monitoring in place for every user in point and every server in the executive branch this is important because it it creates a single view that that we would now have through my office that we can now assess risk we'll have we'll have an individual department level of risk assessment and we'll also have an aggregate risk assessment of how we look as a state across the executive branch in terms of what our threat landscape looks like where our adversaries may have opportunities to exploit vulnerabilities and it will also give us the visibility to see some more of those vulnerabilities are in advance so that we can mitigate some of those in addition to that it also puts up a 24x7365 monitoring platform in place across all the executive branch it will be monitored 24x7x365. it the the the service will be or or is capable of of instantly blocking known signatures and known profiles from a threat adversary without any interaction from anyone on our team if if the if the threat is you know seen on one of the endpoints the service will automatically isolate that endpoint to where there's no threat of you know proliferation or you you know a threat you know extending through our environment and again this is done without the need of someone on a screen this is part of the service that's built into the tool that's a big plus for us from a365 24365 standpoint because it it it's a it's a material positive movement in you know when threatat maturity and security maturity for the state in addition to that we're also working on a risk assessment process and the purpose of the risk assessment process is we're going to we're going to take the threat data and the threat information that we collect off of the endpoint tool and we will we will use that telemetry data to feed into a risk management tool that will create a risk score card by department and again as the state as a whole it gives us a laser focus on on risk and where our where our highest risk is and it lets us develop a a very precise mitigation plan to to go and mitigate those risks you know ultimately reducing our risk at the state level and so this is something I think is is going to be very important as we mature our risk posture and our maturity of cyber posture going forward identity threat protection what we've over the last two years of identity threatat has risen to the top especially in in state government and we and Arkansas is not immune to threat compromises and identity compromises we're seeing those routinely in some cases several up to more you know 10 to15 in a week where we're having indivi individual user identity compromises as a part of our centralized endpoint we're also building in an advanced identity threatat monitoring process and that as well that gives us quicker insight into 11 want an identity could possibly have been compromised we see a lot of we see a lot of attempts on a single identity coming from multiple parts of the world not just in the US and and those are really quick indicators that we know we've got a problem and we can act on those a lot quickly the quicker we can isolate the identity and and reset the credentials on that person's account is it you know it's a step forward for us in protecting and you know that turning into a a business email compromise you know which can be costly in some cases for for fraud and financial reasons and we mentioned earlier I think I think Representative Richardson you brought up the darkk web monitoring we're also going to incorporate a darkk web monitoring process in this endpoint tool as well and what that will do is it will give us an advanced look of do we have identities out on the dark web of of state employees so it gives us some insight if we can see those we may not be able to remove them but we can make sure those accounts are reset and and the credentials are reset and and that will be another layer of identity protection that we will get as a part of our endpoint protection The last the last thing I'll go over with you is incident response we are we we are working to develop what I would call a statewide cyber task force and and and and the purpose of that task force would be for us to improve our readiness and our response readiness in the event that we do have an event or a compromise we will have a you know a a trained incident response team in place that you know that can quickly respond to any number of a level of events or cyber incidents but the main thing it does there for us is it speeds up our readiness and our preparedness so that we we have a team they have the tools they have the skill sets to properly respond to an incident in the in the event that we need to do that we're also working with General Bridges and the and the Arkansas Guard to incorporate the guard into this task force we've had already two or three meetings kind of pulling together what we think a draft of that team might look like so that's ongoing but you know we hope to get that completed early next year so that we have that team in place the team will be representative of individuals from each of the departments especially the larger ones and then we you know we will look to grow that team and to picture of cyber command if you will a centralized cyber command that would be there on the ready to handle not only day to day cyberrelated incidents but also something more serious as a cyber event that we would need to respond to either through adam if you know if if the emergency cyber plan were to be initiated this team would be in a direct response to that to the ESF16. And I think I think that covers everything I wanted to talk to you about today OK so again it sounds like a lot of good
▶ Play Suggest a correction Report an error
Representative Stephen Meeks Unverified 1:03:19
work going on. I have two questions that came up on the the cyberris assessment that you're going to do with each of the different agencies. I I love that idea. the scores that you get from that is that something that would be reportable to the audit committee because I know audit looks at a lot of this and there's some crossover between the two of you. Is that something that could be reported to audit so that as these agencies are audit audited that is made available so that if an agency is not coming up to snuff like they need to be that they can be sitting here at the end of the table explaining why so
▶ Play Suggest a correction Report an error
Gary Vance Unverified 1:04:05
so it's a great question and that that's absolutely what we're what we're out to accomplish here we want we want a you know appropriately we want to put that risk out front so that we can see it right we all of us can see it and understand it it's not meant it's not meant to embarrass anyone it's it's that's not the purpose here but you you just simply cannot mature in cyber if you don't understand your risk and so the goal there is to do exactly as you described and and that that gives the visibility that we need in some areas we may need some assistance in that department it could be funding it could be tools it could be a variety of things that we need to do to mitigate a particular risk. OK and then
▶ Play Suggest a correction Report an error
Representative Stephen Meeks Unverified 1:04:51
the the second question I have is on training our state employees and cyber where are we at with that so
▶ Play Suggest a correction Report an error
Gary Vance Unverified 1:04:59
some of you are familiar with the SL C g p grant that went into effect I get a couple of years ago I guess and so you know the majority of that money is earmarked for for local for state for counties and cities however we we get a s a 20% portion of that grant and so about 18 months ago we stood up what we call the cyber center of excellence and so the approach there is to offer an opportunity to train state cyber resources by utilizing that fund so over the past 18 months we have offered a variety of internal cyber training from basic all the way up to expert we we've funded that with with that grant money and we've made it you know all all you got all you have to do as as a individual they show up for the training we've we've had over the 18 months that we've had the center up we've had approximately500 enrollees going through a variety of courses over that period of time so it's it's been very successful and we want to build on that going forward we've got a couple more years of SLCgp money and we're going to continue to use a portion of that money to fund the cyberenter of excellencecellent
▶ Play Suggest a correction Report an error
Representative Stephen Meeks Unverified 1:06:27
right uhpresentative Collins thank you and this sounds
▶ Play Suggest a correction Report an error
Representative Andrew Collins Unverified 1:06:33
great and I think you guys do a great job and I noticed that you know as it should be in your discussion you're talking about the executive branch of state government so I guess two questions one where do the legislative and judicial branches fall in. I know we have BlR and we have AoC are those considered to be legislative and judicial respectively or are they within your purview somehow and second and maybe my the question I you know kind of dread having you ask because I'm afraid of the answer how are we doing with local government city county school board etc. what kind of resources I know it's not your purview necessarily but how can we help bring them along because I know there's obviously lots of gaps there on the cyprus
▶ Play Suggest a correction Report an error
Gary Vance Unverified 1:07:20
cruz said there are and and the the the Slcgp money that I referenced earlier that's where that money is going directly into counties and and and cities so we're making progress there we're making improvements there trying to follow again a standard model for especially you you know the heretofore the counties and the cities especially the counties they've they've they've been pretty much left up to the individual county to make whatever decisions they wanted wanted to make in terms of cyber and you know we've seen you know really severe third party that that third party risks that get into the county with with a a provider that may not have offered the level of excellence and service that they may have indicated in the beginning I mean you guys will remember when that all7475 counties were subject to a a ransomware event a couple of years ago and and the primary reason of that was because of a third party provider that had had some vulnerabilities and risk in their environment that exposed the counties so you know we're trying to make improvements in assisting with thirdparty risk and third party risk management but it it it it's making progress and we've we've seen less cyber incidents and events in the counties and cities maybe over the past 15 months where we were probably a little more active than we wanted to be with ransomware in those areas you know K12 is particularly been a target for ransomware events we've we've seen reductions there as well we we are we're improving our alignment with K-12 almost daily we're getting them they're coming on board with the centralized endpoint detection and response so there is improvement going on within K12 so progress is being made and that like I said earlier I think there's two more years of SLCgP grant money and that money will go into the counties and cities they have a plan for how they want to spend that money respectively so so improvements are being made on your previous question so my focus and I might get Jay to help me with this answer so right now the focus is on the executive branch but my my thoughts are if we if we build and we develop good cyber programs at the executive branch then it you know constitutional offices judicial offices they can they can fold into those plans at whenever appropriate right but if we if we get good governance and good consolidation and good cyber services and standards in place it it will be relatively easy to roll in
▶ Play Suggest a correction Report an error
Speaker 115 1:10:49
you know the constitutional and judicial offices so and that does answer
▶ Play Suggest a correction Report an error
Representative Andrew Collins Unverified 1:10:53
my question so those are not part of the things that are being off really not part of your purview how about legislative same thing like as far as you know our operations over here, those are just operated separately without necessarily buying we have to be later optional buying into this if we wanted to yes I believe that would be the correct
▶ Play Suggest a correction Report an error
Gary Vance Unverified 1:11:13
answer thank you p re s ent ative Richardson
▶ Play Suggest a correction Report an error
Scott Richardson Unverified 1:11:21
thank you Mr chairir and and if I understand correctly we'll have to do some legislation to make that work for you guys to have the ability to to oversee other areas but I did wanna back up and just touch on one thing you talked a lot about tools tools and endpoints monitoring I'm making the assumption that this is also going not just the end points but you're also hitting the networks and the environment doing active threat searches for those in those space as well ok good other than that what else do you need? Well I
▶ Play Suggest a correction Report an error
Speaker 111 1:11:58
mean we're I feel like we're I feel like we're making great progress
▶ Play Suggest a correction Report an error
Gary Vance Unverified 1:12:03
we you know we're we're doing we're working on a skills assessment with the idea that we can leverage resources that we already have today so that you know it it's not it's not a matter of having to go out necessarily and buy new tools although we are doing that in some cases but we also think that we can generate efficiencies and some effectiveness through what I call shadow IT or or shadow cybertools and we already know we have some of those out there and we we've developed you know early targets for all we know a standard tool may may eliminate multiple tools so I mean I think it's it's just the it's just a continued support that you're giving us today that's been so helpful I mean the legislation to centralize and consolidate was a a really big step for for us because up until now I had no purviews from a cyber perspective over any other department other than OsT so what's been helpful now is we you know we've got the backing and we got the support that we need down to the department level which is which has been huge but I think going forward just you know having having the support that we've already seen that you guys have already given us I think it's tremendous and if we could build on that going forward that would be fantastic. thank you and colleagues at
▶ Play Suggest a correction Report an error
Representative Stephen Meeks Unverified 1:13:43
a lot of times with technology it's generally out of sight, out of mind until the bad guys get through and I just want to let everyone know and I don't don't want to get into any specifics here but under the current law whenever there's a major cyber breach, legislative leadership has to be notified to make sure that we're all on the same page and it's not unusual for once or twice a year for us to get those notifications. So this is an ongoing concern. you guys are doing a wonderful job of trying to whittle that down to zero and appreciate the the work that you're doing on behalf of the state and so I guess last but not least everyone's favorite topic artificial intelligence. so Mr.mcGgo you'll take it away
▶ Play Suggest a correction Report an error
Speaker 90 1:14:28
all right thank you and as one preface to this I did give everyone a copy of the initial report of the Arkansas AI and analyticox Center of excellence. one thing that's changing that it makes some references to the data and transparency panel but we had some recent legislation with Act375 of2025 that sort of matured the data in transparency panel and do a network of data stewards the ddP was really about setting the initial strategy and and and really working out secure governed data sharing integration and and use across the state that's really moving into a more operational phase. we have a longitudinal data system. we have a statewide data hub we have standardized data sharing agreements and all these things and and some set a meeting you know for 90 minutes quarterly to talk strategy we're really kind of moving into a more operational network. so under that Act375, each department will name at least one day to steward but it can be more because it can be per department per division, per program, whatever makes sense at at the time for the department but those data stewards are responsible for operationally cataloging the data very much like the hardware and software that Jay talked about and and then you know as we'll see we'll kind of probably lean on that and do the similar type of thing with AI and for executing the data sharing process the origin of the the data transparency panel and the data hub and all this started with actct 12A2 of20fi5 which really sought to eliminate duplication of data and efforts so that's all part of making sure that everything's catalogs re knows where everything is we don't have duplicate efforts so if if there is a data need by a programmer service that that department can find that data wherever it lives in the state and you have a secure governed way to reach out and get the approvals, share it and so we can eliminate some of that duplication of data and effort. moving on to artificial intelligence we're going to get an update on the AIOE man I had a few of the highlights of the initial report and what's happened since then so we can kind of get into some questions so the the goals of the CIA are we distilled those down at the beginning to protectarkansans in their data to improve government services and to prepare Arkansas for the AI economy representatives from multiple agencies at the House and Senate there are a couple of members on this committee and higher education at the business community that that the chief workforce officer really given us sort of a diverse set of perspectives our methodology for kind of studying this kind of started ro and got specific we did a a wide literature review we looked at the task force reports from other states and every you know come and let we found that from the National Council of State Legislatures they had a a database of about 1600 different pieces of AIlated legislation and looked at executive orders and just really just try to kind of figure out from the states who have already been looking at this since 2019. what have they already done so we don't remit the wheel then to kind of pull it in to to Arkansas we really looked at at Arkansas's priorities we we we broadened out the the group a few months ago AI roundtable where we had all the departments and we had about75 participants really have an all day event talking about a speaker on the national perspective on AI kind of the state landscape and then kind of drilling deeply into more education workforce and healthcare aspects and so we're kind of continuing to to focus in because it's such a a broad and dynamic topic as far as moving from that sort of initial study to the more operational governance aspect we started with the guardrails they're on page five of that report. These are intentionally meant to be very enduring because we know that we're deploying AI technologies today didn't exist a year ago. so these need to be very plain language not bound to specific technologies just very clear common sense you can read it and decide whether it is me in that guardrail or not the next step was starting to implement those guardrails and that really comes down to governance which starts people in process so after we develop the the set up the first report and we've used our our subsequent meetings really starting to iteratively develop and refine an AI governance process. so we developed a set of draft policies around privacy transparency, explainability, human oversight all these kind of key topics in the guardrails and started developing an AI inventory and so kind of point forward as a department had an interest in deploying an AI technology or maybe it was something that came up for renewal they already had it in but we're starting to run it through the governance process we we would kind of work with them kind of assess the risk using the AIris management framework from the National Institute of Standards and Technologies and kind of learn from that but you know what's what's going well what are best practices we can we can replicate what are risks and try to you know streamline that process make it as efficient as possible and now we've kind of moved it over onto the under the the id process that Jay talked about through that we we kind of learned by doing we've had a couple of different pilot projects we're kind of learned there and now we've recently did an inventory across all fi5 departments of AI that's in use or that they plan to use and then going forward this will just be part of the natural itch process under IT governance so we'll we'll have IT governance cybersecurity governance, data governance AI governance you know all interrelated because they all impact each other next was having secure and efficient AI infrastructure and actually we talked about the data hub gives us a a strong strategic advantage there as a state because the the day the AI is only as gs today to from which it's being fed and so we we kind of recommend you know it leveraging the data hub leveraging the the data governance controls that are there and extending it for AI governance and just you know naturally extending that environment as needed to harness the the capabilities of AI safely to deliver better citizen experience you know efficiencies where we can find them and then capacity building we we've got our governance we have our our safe environment in which to to harness AI but you know people have need to know how to use it so page six has a four tier framework where we kind of you know we've got executive AI training you at the there needs to be some highleve understanding and and we've done back in January February during session we did an AI executive briefing for some of the legisl ator s but we know that you know we we probably need highle sort of AI literacy for departmental leadership and state leadership we need the AI training for just general state employees I think that goes along with with cybersecurity training making sure people know where it's safe to use AI where they're going to be impacts making sure people know what what data is safe to put in what environment and for what purpose the the deeper technical training for those the state employees who are actually implementing and maintaining these systems and then the more professional training for just the roles that are that are being impacted by and that's that's change in the processes lastly looking at a different part under our our purview is that the state longitudinal data system and the economic security report which is consumer information used by Every7th to 1elth grader, every incoming college freshman other adult learners for their career exploration and planning we realized that we need better information on how AI is changing labor market demands so they can make informed decisions so we've got some efforts underway to improve our data collection and reporting on the labor market impacts of artificial intelligence. so we've kind of walked through all that we've kind of we're pulling together and disseminating our our kind of our next set of recommendations now and I think we we're we'll continue to have some pilots and just really operationalized this under the itch process and the overarching IT governance.
▶ Play Suggest a correction Report an error
Representative Stephen Meeks Unverified 1:24:12
thank you gentlemen for your presentation. so definitely off to a good good start here this past summer I had a chance to attend AI4 and I don't know if you're familiar with that or not but AI4 is the largest artificial intelligence conference held annually in North America. there were 8000 people from like50 different countries. I was one of only three state representatives that was there and I was actually asked to speak on one of the panels and so that was in a room full of about300 AI businesses to give this presentation and one of the things that I told them was is they're generally you know they like to focus on the big states you know the Florida, the Texas, theor is where all the where a lot of these resources come from and I encourage them to look at the smaller states like Arkansas I said Arkansas a lot for for hopefully obvious reasons because I think one of the benefits that we have as a smaller state is we can be a lot more flexible and nimble in this space. this is as you I think everybody in this room realizes AI is going to be a transformative technology and the first state that can figure this out and do it right is going to get a huge advantage over our sister states that's economically education all all the way up and down the line and so as we're moving forward on this, I think our state has the potential because we're smaller and can be more nimble. we have the opportunity here to be a a leader in this space one of the presenters and this is this is a business owner one of the things that he had done in order to help get his employees trained up because I I think you know and and I changed the law to require AI technology use policies across the state but at the same time my concern is is that if we do from a top down we're limiting our opportunity to take advantage of this with several of the businesses said that they did was they created opportunities for state employees they gave them say an hour or a week,2 hours a week and set up a sandbox and let the employees just play with the technology for an hour or two a week. no strings attached do what you want learnarn the technology and he said that once he did that his employees figured out how to use that technology, implemented into their workflow and now his business the employees were able to use AI in complete within an hour what used to take weeks to get done and obviously that created a huge huge advantage for for his company. and I would love to see us as a state implement a similar strategy because you know like with the cybersecurity if we say hey come take this class there will be some people that that do it right but then they take the class what happens if the average state employee is learning how to use this not only does it it it gives them a skill to better prepare them for the future but because they're the ones doing the job day in day out they would be much better equipped to figure out how can I implement this to make my job better? How do I use this tool? right? I I'll see her up at this level. we can't we can't come up with all those thousands of use cases out there and so how do we unleash our state employees to have that opportunity to do to do that and so that that's the challenge I'm gonna put out to you and to you know Department of you know transformation and shared Services how do we create the opportunities for our state employees the average person who's you know, taking the phone calls doing the evaluations how do we allow them to unleash this technology for their jobs obviouslybviously we got to have the guardrails in place you guys have already worked on that according to the report but I would like to see us really jump on this because if we don't as a state and we come in last nobodydy likes you know none of us up here want to see Arkansas in41st place or4fith place when it comes to this technology we want to be in the top 10 and in order to do that I think the way that we need to go about doing this is giving these tools with the proper safeguards in place to all of our state employees learn learn this technology, learnn how to use it for your job Once you kind of figure out a use case, bring it to your supervisors and let's see what we can do to do to implement it I don't know if you have any thoughts on that how do we go about implementing it but I would love to hear your feedback on it now I will say after I predicated that everybody at that conference business government and again these are from fi050 different countries as well the prevailing thought was we all need to do this and everybody thinks they're behind right and so there's a sense of urgency here but at the same time I want to be smart. I want to take advantage of this to make sure that we become a a a national leader on this I want other states to be looking at Arkansas to figure out how to do this so would love to hear your your feedback on this. and and I completely agree and we're and so far
▶ Play Suggest a correction Report an error
Speaker 86 1:30:10
we're we're not last code for America's put our report that that and a dashboard and everything that that a lot of people are looking at and it's it's at
▶ Play Suggest a correction Report an error
Speaker 90 1:30:17
four stages and are already up to the second the developing stage and there's a good number of states still in that that first stage and I think pretty soon we'll be moving there's only three states in that top stage right now I think it's California, New Jersey and Pennsylvania and we're working our way up to that that third stage and we spent a lot of time looking at America's action plan which really talks about the need to to move quickly rapid adoption of AI at scale and and the key barriers to that and you have to have a a literate workforce and people have to dress in in that and so we're you know I think the governance the the secure infrastructure you know literacy the these are all some of the key ingredients to have in the trust so that we can move fast and realize the advantages right yeah cause because that the last
▶ Play Suggest a correction Report an error
Representative Stephen Meeks Unverified 1:31:08
thing I want to happen is y'all to work up all this and then it stop, right? we've got to get this out to the state state city I mean my count folks in the county are asking me, hey, how do we implement this at the county level right and so obviously a sense of urgency here uhpresentative Richards you're up sir.
▶ Play Suggest a correction Report an error
Speaker 107 1:31:30
thank you Mr Chair. if I didn't ask a question it would be odd right? so
▶ Play Suggest a correction Report an error
Scott Richardson Unverified 1:31:36
yeah question for you have you started receiving requests for AI tools specific tools to do specific jobs like traffic engineering or or what have you. I know that there are a lot of AIbas tools that are starting to come to market at this point and I'm wondering if you're seeing requests for those types of tools from the state government if you've started compiling lists or determine how you're going to go about implementation what kinds of processes you're going to go through for review any of that kind of stuff
▶ Play Suggest a correction Report an error
Speaker 90 1:32:05
yes and that's the AI use case inventory and and now as part of the the age process so in which the the itch process is whenever somebody wants to make a purchase or procurement but also if they're just doing an information technology project so in in many cases the AI capabilities are emerging in tools that have previously been procured so it it doesn't necessarily have to have a cost associated with it but so we kind of drew that line with you know production deployment of AI but we've seen a lot of early things around document summarization query a lot of things to help with legal documents a lot of improvements to overoCR to to scanned text translationative yeah a lot of geneative
▶ Play Suggest a correction Report an error
Speaker 86 1:33:04
there's been a a fairly broad variety not not the specific ones you looked at well I'm I'm I'm just going from my own experience so obviously that
▶ Play Suggest a correction Report an error
Scott Richardson Unverified 1:33:15
that I'm sure there are all AI tools coming around for a lot of the the day to day task and providing oversight and review and I'm just curious how much of that we're actually seeing and most of the time we're going to get that from what uhpresentative Meeker chair was speaking to is that's coming at the lower level they're seeing this or that if they go to a conference and this this tool's coming up and just you know how are we managing those how are we discussing those those are coming to the standard procurement process and they get the standard reviews associated with everything else do we actually have the policy for AI use pass through the various departments at this point or we're still working to develop that I guess that was part of that discussion but I didn't really get I know you have some points of the policy that you're bringing together but do we actually have an AI use policy that's in place the full acceptable use
▶ Play Suggest a correction Report an error
Speaker 90 1:34:09
policy is not currently published. I think it's it's pretty close but we've we've been developing it testing out of real world reviews through the AICE giving provisional approvals and it's a I think we're probably getting close to a point where we can formalize that and kind of put it in place to the the data sources so if you don't mind what's the process for approving a tool that has an embedded AI functionality if we don't have a policy and we're largely kind of aligned with the the nestris management framework so depending on the the nature we might start with asking them some questions initially about OK what you know what type of data involved what's the sensitivity you know is this for resident facing as a staff facing what's the impact if a decision is you know made that that's erroneous things like that to to kind of understand the risk in its place within that risk management framework and then what sort of control to mitigate those risks and then if it was a particularly interesting when you know like on the either in the scale and kind of like bring that to our get on the agenda at AICE meeting so we could really kind of take a more indepth look and have a lot of discussions and kind of run it against these policies to see with with these specific examples will these policies work in practice when we're really starting to see lots and lots of these and we've really been seeing an uptick over the past really about like the past 90 days there's been you know a marked uptick in the the interest in deploying these technologies but we're also seeing common patterns so we're hopefully we'll we'll go from a a tech technology procurement standpoint of what Jay was talking about economy to scale kind of using shared services and getting some consistencies there we'll also kind of hopefully have some cross pollination of best practices around similar use cases yeah and of course from my seat I have a lot of concerns
▶ Play Suggest a correction Report an error
Scott Richardson Unverified 1:36:17
you know it reminds me a lot of when Microsoft started producing access right? Microsoft Access and you had all of these businesses going these are great and then they would build this little bitty piece that would do this little bitty thing and then somebody said hey that's cool let me use it and then the next thing you know it's a business dependent kind of function that's spread out all over the place and it's hard to get rid of and not built for that so I see the same kinds of things with a lot of the AI tools it's a little bitty thing that does this and the next thing you know 15 people have adopted it and now you've got this sprawl and the challenges associated with managing that so anyway I appreciate the answers. good luck with implementing the policy it's gonna be fun on on that last point
▶ Play Suggest a correction Report an error
Speaker 90 1:37:01
there's a center forublic sector AI that 26 states are participating in that kind of gets us together and with you did a response office management budget and others and director of andB was letting us know that you know we have an opportunity here because unlike the way IT is kind of unfolded in the past we all you know we have a chance to do this all at once so this is our best chance right now to to really kind of get ahead of some of that sprawl and make some wise decisions on the front end and think that that's why we're we're really being particular about the the governance I noticed one of the recommendations
▶ Play Suggest a correction Report an error
Representative Stephen Meeks Unverified 1:37:37
you have in here is that we need to maybe see about creating a position for a chief AI officer, so obviously you're main focus has been data and data governance. so can you kind of talk to us about the need for that role versus what you're role is. I mean it seems like kind of like you're doing a dual role right now but do we still need to get an AI person and what does that position look like? is that gonna require legislative legislative action in order to create that role and what would you see a person in that role doing? So can you kind of flesh that recommendation out for us
▶ Play Suggest a correction Report an error
Speaker 86 1:38:22
and I can speak to the deed and and Jay about the mechanics but as far as the need I think they're essentially they're both very
▶ Play Suggest a correction Report an error
Speaker 90 1:38:29
full time jobs it's there's a lot going on with both data and AI and they're they're related but that they both require a lot of focus especially when you're you're really spread across 15 different departments and and all of the different things going on right now with you know data related HR one implementation and you know AIs evolving and you know it's quite a bit so I I definitely say that it it requires at least two people to cover all of that if we want to kind of take a a a national leadership stance yeah and I mean we would just come to personnel committee and ask for
▶ Play Suggest a correction Report an error
Speaker 85 1:39:08
that position officef of state Technology probably already has a position that we can just change the title on. OK so is that something that you're
▶ Play Suggest a correction Report an error
Representative Stephen Meeks Unverified 1:39:16
looking to pursue in the near term or is that just an option or kind of where are you or where you're thinking on what we want to do with that
▶ Play Suggest a correction Report an error
Speaker 85 1:39:26
I would probably say at least probably 1st quarter of 2026 if not sooner right excellent OK. all right
▶ Play Suggest a correction Report an error
Representative Stephen Meeks Unverified 1:39:32
colleagues any other questions? I know we've we've covered a lot today and so yeah it's a lot a lot to get our minds around all right well seeing none gentlemen thank you for being here and for sharing with us the work the very important work that you're doing for the citizens of our state and we look forward to more updates in the future. all right colleagues again, I appreciate y'all hanging with us for all this a lot of important discussions today seeing nothing else on the agenda we are adjourned
▶ Play Suggest a correction Report an error

Agenda

A. Call to Order

1:24

B. Consideration to Approve the April 23, 2024, Meeting Minutes [Exhibit B]

1:41

C. Consideration of a Motion to Authorize Chairs to Approve Special Expenses Incurred by the Committee

1:52

D. Discussion of Cybersecurity [Exhibit D]

37:37

E. Discussion of the Arkansas AI and Analytics Center for Excellence (AI CoE)

51:19

F. Discussion of DeleteMe [Exhibit F]

2:25

G. Other Business

1:39:57

H. Adjournment

1:40:01

Speakers

Representative Stephen Meeks Unverified
56 segments
Taylor Tabner Unverified
3 segments
Speaker 11
2 segments
Senator Breanne Davis Unverified
63 segments
Speaker 22
5 segments
Speaker 46
1 segment
Representative Matt Brown Unverified
2 segments
Speaker 54
1 segment
Representative Andrew Collins Unverified
6 segments
Scott Richardson Unverified
17 segments
Speaker 85
3 segments
Speaker 86
4 segments
Gary Vance Unverified
42 segments
Speaker 84
32 segments
Speaker 115
1 segment
Speaker 111
1 segment
Speaker 90
33 segments
Speaker 107
1 segment