Secretary of Information Technology, duties regarding cybertechnology technology quality assurance for state agencies further provided
HB208 expands the duties of the Secretary of Information Technology and the Office of Information Technology to explicitly include cybersecurity governance for state agencies. It amends Section 41-28-4 of the Code of Alabama 1975 to authorize the secretary to adopt rules, regulations, policies, and procedures covering state IT management, including cybersecurity controls, project management standards, enterprise architecture, and technical assistance to agencies. The bill also directs the office to continue coordinating statewide IT planning, budgeting, procurement, asset management, and reporting.
A major new feature of the bill is the creation, by rule and in consultation with the Governor, of a technology quality assurance board. That board would oversee the responsible and transparent procurement, development, and use of novel technologies, including artificial intelligence, in state agencies. The bill requires ethical guidelines, security and privacy controls, and ongoing compliance mechanisms for those technologies. The act would take effect October 1, 2025.
HB208 would broaden the statutory authority of the Secretary of Information Technology by adding express cybersecurity governance responsibilities and by allowing the office to establish a technology quality assurance board through rulemaking. It would affect state agencies by subjecting their IT systems, cybersecurity practices, and adoption of emerging technologies to additional statewide standards, oversight, and coordination. The bill does not create a new agency in statute, but it authorizes new administrative rules and oversight structures that could influence procurement, project approval, and technology use across state government.
The available context suggests the bill is being treated as a government modernization and oversight measure rather than a controversial policy shift. Its focus on cybersecurity, responsible technology use, and AI governance indicates a generally favorable or at least pragmatic posture toward improving state IT management. There are no recorded votes or committee transcripts in the provided material, so there is no direct evidence of opposition or support beyond the bill’s introduction and pending committee status.
The main potential point of contention is the scope of executive and administrative authority the bill gives the Secretary of Information Technology and the Governor in setting rules for cybersecurity and the new technology quality assurance board. Another possible concern is how the board’s ethical, privacy, and compliance requirements would be implemented for emerging technologies such as artificial intelligence, especially if agencies view the rules as adding procurement burdens or slowing innovation. No specific objections are recorded in the provided history, so these are inferred areas of likely debate rather than documented disputes.