
In 2022, nearly half of US state CISOs said they were confident in their ability to protect public data. Today that number is 22 percent. That is not a gradual erosion, it’s a collapse. The 2026 NASCIO and Deloitte Cybersecurity Study makes clear what is driving it: AI tools are being deployed faster than any governance framework can track them, and the security baseline has not changed.
The report highlights the rapid spread of ungoverned AI tools and vendor enabled GenAI, aka shadow agents. State agencies are still relying on written policies to govern autonomous systems that do not read policies. Furthermore, only 22 percent of staff currently possess the required security competencies, down from 48 percent in 2024. The human element is overwhelmed, and legacy security measures are failing to scale.
AI tools are being deployed faster than any governance framework can track them, and the security baseline has not changed.
Government agencies should not have to compromise citizen privacy to extract insights from their data. However, with 94 percent of CISOs actively developing GenAI security policies, the industry focus remains heavily skewed toward written rules rather than infrastructural enforcement. This is a failing strategy, especially as 16 percent of CISOs are now facing budget cuts, compared to zero in 2024. Security teams need to do more with less. Cryptographic infrastructure that automates compliance and reduces headcount dependency is the only viable path forward.
This is exactly why OpenMatter built the trust layer for secure computing. We have moved the baseline of security from software promises to verifiable mathematical execution. Instead of centralizing raw public records, our Secure Data Collaboration protocol allows AI agents to safely interact with datasets on behalf of human operators. Simultaneously, the OpenMatter ZK Firewall acts as a gatekeeper that cryptographically prevents shadow agents from executing unauthorized actions. Agents cannot leak datasets they never possessed.
Deep Dive
The NASCIO report dedicates an entire section to the "Whole-of-State" approach, emphasizing the urgent need for states to share security resources and data across municipal agencies, K-12 schools, and public universities. When Health and Human Services needs to share intelligence with the Department of Education without exposing raw records, legacy architectures present a massive security risk.
Secure data collaboration bridges this exact infrastructure gap. By utilizing Secure Multi-Party Computation (SMPC), the computation is distributed to the edge. The data is secret shared, ensuring strong, mathematically verifiable privacy guarantees. It is collaboration without compromise.
Additionally, the report specifically flags third party security breaches as a growing concern. The ZK Firewall neutralizes this threat through its agentic execution compliance gate. It mathematically proves that external or vendor enabled agents are only performing approved executions before any data exchange occurs, fully securing the state’s perimeter from compromised supply chains.
OpenMatter is actively working with enterprise and public sector design partners to validate secure data collaboration across highly regulated environments. If your organization is ready to move beyond policy based security to verifiable cryptographic execution, join us:
Apply to be a design partner at https://onboard.openmatter.network to scope a solution for your agency.
Subscribe to the OpenMatter newsletter to stay ahead of the agentic compliance curve:
References
Deloitte 2026 NASCIO Cybersecurity Study: https://www.deloitte.com/us/en/insights/industry/government-public-sector-services/2026-nascio-deloitte-cybersecurity-study.html
SecureWorld State CIO & CISO Report 2026: https://www.secureworld.io/industry-news/state-cio-ciso-report-2026


