Insights

September 08, 2026

What Federal IT Leaders Are Choosing Amid New AI Capabilities

Ryan Haylock is Chief Information Officer at Evolver, a federal technology and cybersecurity firm headquartered in Reston, Virginia. He has led IT and cybersecurity organizations across commercial, private-equity, higher education, manufacturing, and elder-care sectors with a focus on operationalizing cybersecurity efficiently, smart process automation, and building highly performing teams. 

Federal IT looks different in 2026 than it did a year ago. As workforce numbers compress and procurement consolidates, new AI capabilities are landing on federal platforms. This shift is happening whether the supporting operating models are ready or not. The question I find sitting underneath most federal IT conversations this year is not which tools to buy or which talent to hire. It is what the operating mix looks like across internal staff, contracted partnerships, and supporting technology, and whether that mix will actually deliver. 

This is at the heart of the Capability Mix question: At what rate are these inputs now moving? 

The mix as a portfolio of partnerships 

Federal IT conversations often describe the capability-mix decision as a sequence of separate procurement and staffing choices. A contractor task order on one workstream. A managed service contract on another. A platform upgrade somewhere else. A hire when the budget clears. Each decision gets evaluated on its own terms. 

The federal record over thirty years tells us where that approach ends. The transactions are individually defensible. The aggregate is something nobody designed. 

The framing I have come to find more useful, across HIPAA, SOX, FERPA, and ITAR-adjacent regimes before this seat, is that the capability mix is a portfolio of partnerships. Internal staff with their own leaders. Contracted partnerships with managed service providers, integrators, and capability vendors. Technology partnerships with platforms that augment human capability. The forms are different. The disposition that makes any of them perform is not. 

This is familiar territory for federal contracting. Twenty years of federal acquisition literature has emphasized the buyer-seller relationship as the core unit of federal IT delivery, with explicit attention to trust, expectations, and honoring commitments inside a contract structure that defines the work.  

The literature holds up. Contract administration doctrine has engaged with post-award performance management for decades. What I would add to that long-standing conversation is the operating-disposition lens: the year-over-year work of making a partnership perform, inside whatever contract structure shapes it, is what determines whether the capability-mix decision delivers on paper or in practice. 

The contract sets the conditions. The disposition operates within them. 

Why the question is sharper now 

The Government Accountability Office (GAO) reported in June 2026 that the civilian workforce across the 22 CFO Act agencies declined by approximately 256,000 employees, more than 11 percent, from December 2024 to January 2026 (GAO-26-108583). Eighteen of the 22 agencies posted declines above 10 percent. Some agencies declined by more than 30 percent in a single year. 

Federal IT spending has not contracted alongside that workforce. GAO reported in July 2025 that the federal government spends more than $100 billion annually on IT and cyber-related investments, and that agencies typically spend about 80 percent of that on operations and maintenance of existing systems (GAO-25-107795). For fiscal year 2025 specifically, that came to roughly $83 billion of $105 billion. 

The EY 2026 Government and Public Sector Federal Trends Report surveyed 131 federal agency leaders and named the workforce skills gap as the single most commonly cited barrier to modernization, at 44 percent of respondents. Slow procurement and cybersecurity threats followed at 32 percent each. 

The mission has not contracted either. CMMC Phase 2 begins this November. Federal post-quantum cryptography migration runs on a NIST-published timeline through 2035. Procurement consolidation under the OneGov strategy is reshaping the vehicles through which federal IT capability is acquired. Compliance obligations are growing. Internal capacity to deliver them has shrunk. 

Federal CIOs are absorbing the gap. The choice they are making, often without naming it as a single choice, is what their operating capability mix will look like across internal staff, contracted partnerships, and supporting technology. 

Where AI enters the mix 

AI augmentation in federal IT operations is no longer a future question. The GSA and ServiceNow announced a OneGov agreement in September 2025 that made AI-augmented IT service management broadly available to federal agencies at substantial discount through September 2028. Federal agency leaders themselves confirm the direction: the EY 2026 report found 92 percent view AI as a critical tool for improving efficiency, and 86 percent report barriers to scaling it agency-wide. Only 38 percent said they have a comprehensive, unified AI governance strategy in place. 

Read those numbers together and the picture is clear. Federal IT leaders see AI as necessary, but most are not yet operationally ready to use it well. 

AI delivers real value in federal IT operations when the operating model around it is built to absorb it. Routine triage, summarization, pattern recognition across incidents and requests — these are exactly the kinds of workloads that scale well with AI and free analyst time for the judgment-heavy work that only people can do. That is augmentation, not replacement. Done well, it realistically lets  federal workers spend their time on the work that matters. But without an operating model behind it, AI produces an expensive layer that adds complexity rather than absorbing it. We’ve seen this happen with every wave of federal IT tooling purchased ahead of establishing the discipline needed to run it effectively. 

Federal AI carries real constraints: Data sovereignty; Governance; Model auditability; Integration with existing identity and access frameworks. These are not arguments against federal AI. They are the conditions under which federal AI works. Federal IT leaders who are getting value from AI in service operations today treated those constraints as design inputs from the start, paired the AI with the operating discipline to govern it, and made the technology part of a broader partnership portfolio rather than a freestanding purchase. 

The capability-mix lens applies to AI the same way it applies to everything else. Technology earns its place when the operating model around it is real. 

What partnership disposition requires 

Four anchors for any federal CIO or CISO making capability-mix decisions in 2026. These are not Evolver-specific. They are conclusions any federal IT operator arrives at after watching enough capability mixes succeed and fail. 

  1. Frame each partnership as integrated within the contract structure that shapes it. A firm-fixed-price relationship behaves differently than a time-and-materials arrangement, which behaves differently than a cost-plus-award-fee vehicle. What makes any of them perform is clear roles, shared metrics, regular review, and mutual accountability — inside the specific cadence the contract allows. The single most consequential conversation a CIO can have at the start of a partnership frames it as an integrated relationship with named obligations on both sides, including the CIO’s own obligations for clarity, prioritization, and feedback. 
  1. Build the visibility your data does not yet provide. GAO found in September 2025 that most of 23 civilian agencies could not tell them the size and cost of their own federal and contractor cyber workforce. The figures agencies did produce — 63,934 federal and 4,151 contractor staff at an annual cost of $14.6 billion — were incomplete on their face (GAO-25-107405). Most federal CIOs know this is the case in their own environment and are working against it. Building that visibility is not glamorous. It is the precondition for deliberate capability-mix decisions rather than absorbed ones. 
  1. Recognize the procurement vehicle you inherited. Federal IT work varies across operations, mission, security, and modernization domains. A 24/7 service operations partnership needs different governance, cadence, and accountability than a multi-year modernization engagement, and both look different from an AI-augmented capability partnership where the technology is evolving quarter to quarter. The right structure for each is rarely a free choice. It is shaped by IDIQ vehicles, GSA schedules, and BPAs architected years ago for different use cases. The work is to see where the inherited vehicle fits the partnership, where it constrains it, and where it is worth advocating for a different acquisition strategy. 
  1. Build discipline that outlasts you. Federal IT lives through administration changes, agency reorganizations, appropriations cycles, and turnover in both the CIO seat and the contracting officer seat. The disposition has to survive all of it. Operating models that depend on a specific person do not survive the next reorganization. Operating models built into governance structures, named accountabilities, documented expectations, and stable cadence do. 

The disposition for 2026 

The capability-mix question is not new. It has been a central question of federal IT delivery for a generation. What is new is a workforce that compressed in a single year, procurement consolidation reshaping the acquisition landscape, and AI capability widening the options available faster than most operating models are absorbing it. 

The federal CIOs who will deliver in this environment are the ones who treat the capability mix as a deliberate portfolio decision instead of the accumulated residue of separate transactions. AI augmentation is part of that mix now. It will deliver where the operating model is built for it, and it will disappoint where it is not. 

The contract sets the conditions, the disposition operates within them, and the work compounds across years. 

So does the absence of it. 

Sources 

  • GAO-26-108583, Federal Agency Workforce Changes: Update for July 2025 to January 2026, Government Accountability Office, June 17, 2026. 
  • GAO-25-107795, Information Technology: Agencies Need to Plan for Modernizing Critical Decades-Old Legacy Systems, Government Accountability Office, July 17, 2025. 
  • GAO-25-107405, Cybersecurity Workforce: Actions Needed to Improve Size and Cost Data, Government Accountability Office, September 4, 2025. 
  • EY Government and Public Sector Federal Trends Report 2026, Ernst & Young, April 2026. 
  • General Services Administration, GSA and ServiceNow Strike Landmark OneGov Deal to Accelerate AI-Driven Government Modernization, news release, September 3, 2025. 

About Evolver

Evolver, headquartered in Reston, Virginia, is a technology company serving government and commercial customers by addressing client challenges in the present and transitioning clients to the future through innovative IT transformation and cybersecurity services and solutions.

Founded in 2000, Evolver delivers mission-driven services and solutions that improve security, promote innovation, and maximize operational efficiency. For more information, visit us at www.evolverinc.com or on LinkedIn.