Citizen Portal
Sign In

Get Full Government Meeting Transcripts, Videos, & Alerts Forever!

Get email alerts on the Agency Digital Services Ai Cyber It Modernization topic

No spam. Unsubscribe anytime.

Agency of Digital Services outlines AI inventory, security priorities and IT modernization projects

2145809 · January 23, 2025
AI-Generated Content: All content on this page was generated by AI to highlight key points from the meeting. For complete details and context, we recommend watching the full video. so we can fix them.

Summary

Denise Riley Hughes, secretary and state CIO, briefed the Senate Government Operations Committee on the Agency of Digital Services’ priorities: artificial intelligence governance, cybersecurity monitoring, enterprise standards, and ongoing modernization projects including Workday for HR/finance and an unemployment modernization effort.

Denise Riley Hughes, secretary of the Agency of Digital Services and Vermont’s state chief information officer, told the Senate Government Operations Committee on Jan. 23 that the agency has shifted into an organizational maturity phase focused on standards, predictability and user experience across state IT systems.

Hughes said the agency now houses a combined data and artificial-intelligence division and maintains an AI inventory that lists more than 37 AI systems in use across state government. She described the agency’s approach as “human in the loop,” stressing that the state’s AI code of ethics requires disclosure and human oversight for systems that affect people.

Why it matters: The agency’s work affects how Vermonters interact with government websites and services, how personal data are handled and how the state defends systems against frequent cybersecurity probes. Committee members requested more detail on AI governance, data-privacy recommendations and the agency’s security posture.

What the agency reported: Hughes listed three near-term strategic priorities: improving user experience so Vermonters can find and use services more easily; setting and enforcing technical and procurement standards; and improving predictability of IT spending through enterprise contracting and lifecycle planning. She said the agency manages enterprise platforms (for example, a statewide productivity/cloud suite), operates an enterprise project office with dozens of active projects, and consolidated shared-technical staff into “enterprise services” to improve supportability and standardization.

On AI: Hughes said Vermont was an early adopter of a state AI director and an AI advisory council and that the agency publishes annual AI inventory and council reports. The council produced a code of ethics and a user guide; Hughes said the council reviews the guidance annually and the agency seeks to hold vendors accountable when they enable AI in contracted products. “We don’t think that AI is an opportunity to replace people,” she said, describing the “human in the loop” approach.

On cybersecurity: The agency’s security operations center monitors high volumes of scans and probes. Hughes said the state receives “millions” of automated probes and that the agency tracks trends, works with the Vermont Intelligence Center and Department of Public Safety, and is increasing monitoring coverage on systems that were previously unmonitored. The committee asked for an aggregated breakdown of routine automated scans versus attempts targeted at Vermont systems; the agency said it can provide follow-up information.

On modernization projects: Hughes summarized several active, state-funded modernization efforts: (1) an enterprise resource-planning/workday program to replace older HR and finance systems, (2) unemployment insurance modernization (the vendor and platform align with other large projects), (3) DMV driver’s license modernization (phase 2 approaching completion), and (4) a network modernization procurement currently in an independent review stage.

Committee direction and next steps: Senators asked the agency to share its AI code-of-ethics materials, the AI inventory, and any analyses the agency uses to assess privacy and vendor risk. Members also requested a short briefing on security incident volumes (routine probes, denial-of-service activity, and targeted attacks) and asked the agency to assist the legislature with data-privacy deliberations this session.

Ending: Hughes said the agency will deliver updated strategic materials and documentation to the committee and offered to return for further hearings on AI, data privacy and project status updates.