09/29/2026 | Press release | Distributed by Public on 09/29/2026 05:09
Every state Medicaid agency in the country is being pitched AI right now. The ones that are actually ready to use it look different from the ones that are not, and the difference usually has nothing to do with the model.
The clearest recent proof is the Medicaid unwinding. When the pandemic-era continuous enrollment requirement ended in April 2023, enrollment sat at a record high of roughly 94 million people, and states had to redetermine eligibility for all of them. By the time most states finished, more than 25 million people had been disenrolled and more than 56 million had their coverage renewed, according to KFF's tracking. The detail that matters for this conversation is why people lost coverage. Nationally, about 69 percent of disenrollments were procedural, meaning the state did not have enough current information to confirm someone was still eligible, not that the person was found ineligible.
Procedural churn is a data problem wearing a policy costume. The states that avoided most of it were the ones that could run renewals ex parte, confirming eligibility automatically against income, employment, and other data the state already held, without sending a form into the mail and hoping it came back. Arizona was among the strongest performers in the country on this measure, completing renewals ex parte at a rate of 90 percent or higher, alongside North Carolina and Rhode Island. At the other end, states such as Pennsylvania and Texas completed as few as 11 percent or fewer of their renewals automatically and leaned on paperwork instead. Same federal policy, same deadline, very different outcomes for real people. The variable was infrastructure and the data matching it made possible.
This is what "AI-ready" looks like in practice, and it is worth being precise about it, because the phrase gets thrown around loosely. Medicaid data is unusually fragmented even by healthcare standards. It sits across the MMIS, the eligibility system, managed care encounter feeds, behavioral health systems, and social care records, each with its own rules and its own idea of who a person is. A state that has done the unglamorous work of unifying those sources can put AI to work on top of them. A state that has not will find that its model inherits every gap and mismatch underneath it. West Virginia's experience is instructive here: unifying child welfare, child support, childcare, and eligibility into a single integrated system changed what was operationally possible, because the data finally described a whole person instead of several partial ones.
The room agreed on where the pressure is greatest. When we asked where operations most needed AI to help, eligibility and redeterminations ranked first by a wide margin, and data quality and interoperability ranked second. Those two are the same problem viewed from two angles. You cannot automate eligibility well until the data feeding it is complete and current, which is exactly what the unwinding demonstrated at national scale.
When people talk about AI governance in Medicaid, the conversation jumps straight to bias testing. Bias matters, and models trained on commercial populations tend to underperform for the diverse populations Medicaid serves. But the layer most panels skip is where the real work sits: data provenance, access rights, and consent. Substance use disorder records are the clearest example. Under 42 CFR Part 2, a member's SUD treatment record does not flow into a model just because the model would find it useful. Consent governs it, and this is a live obligation, with enforcement of SAMHSA's updated rule beginning February 16, 2026. If a state cannot show where a data element came from, what consent covered it, and who was allowed to see it, no amount of bias testing will make the system defensible.
Most AI in Medicaid today arrives as point solutions. One tool for eligibility, another for prior authorization, another for fraud detection, each trained on its own slice of data and blind to the others. Each can show a demo that works. The trouble is that ten disconnected tools do not reduce fragmentation. They add to it, because now the agency is coordinating ten data flows, ten vendors, and ten governance stories instead of one.
Program integrity is a useful test case, because it is often held up as the most mature Medicaid AI use case and it is also the most misunderstood. The improper payment rate is frequently cited as evidence of rampant fraud. It is not. The Medicaid improper payment rate was about 5 percent in 2024, and both KFF and Georgetown's Center for Children and Families note that most improper payments stem from missing or insufficient documentation rather than from fraud or ineligible enrollees. Read that carefully and it reframes the whole use case. A large share of what gets labeled waste is actually a data completeness problem. An anomaly detector bolted onto incomplete claims data will generate false positives that flag legitimate providers and legitimate claims, which erodes exactly the trust the room said it was worried about. The same tool running on a unified, well-governed foundation can tell the difference between a documentation gap and an actual pattern of abuse. The model is not what separates those two outcomes. The data underneath it is.
That is the shift worth naming. When AI operates across a shared foundation that carries clinical, eligibility, encounter, and financial context together, it can work across functions instead of one at a time, and it can carry its governance with it. Eligibility, administrative burden, and program integrity stop being three separate projects and start being three views of the same well-governed data. The realistic version of this today is narrower than the marketing, and agencies are right to be skeptical of anyone who claims otherwise. But the direction is clear, and it runs through the foundation, not the model.
We closed by asking the room to finish a sentence: by 2030, AI will have made our program more ____. The dominant answers were efficient and effective, surrounded by automated, streamlined, productive, cohesive, and reliable. That is a group that expects real operational gains and is planning for them.
It is worth sitting with the smaller words too, because they were honest. Challenging. Complex. Expensive. Dumb. Skynet. A meaningful minority in the room expects this to be hard, costly, and easy to oversell, and they are not wrong to. The capability most likely to be oversold between now and 2030 is autonomous decision making with the governance figured out later. The capability most likely to quietly become standard is the unglamorous one: unified, observable, well-governed data that makes everything above it more trustworthy. The programs that treat the second as the prerequisite for the first will be the ones whose 2030 actually looks efficient.
If there is one thing the room taught us at MESC, it is that Medicaid leaders are already ahead of the vendors on this. They named trust as the barrier before we could. They ranked eligibility and data quality as the places they need help, which are the same place. And they told us, through a poll they answered anonymously, that most of them could not yet explain an AI decision to an oversight body with confidence.
That is not a reason to slow down. It is a map. The foundational investment a director should make first is the one that has to be true before any of the rest works: unify the data, govern it so provenance and consent travel with every record, and make the whole thing observable enough that a person can explain what happened and why. Do that, and the models, when they arrive, inherit context they can be trusted with. Skip it, and AI becomes one more fast way to be wrong at scale.
In Medicaid, AI is a data and trust problem first. The room already knew it. The work now is building for it.