What the State's digital storefront reveals

An automated measurement using artificial intelligence evaluated the websites of 338 Costa Rican public institutions. The results show an extended technical foundation, gaps concentrated in accessibility and privacy, and a weaker-than-expected relationship between transparency and digital quality.

Date
Author
Marlon Ávalos Elizondo
Topic
Artificial Intelligence
ICDI 2026
Figura 1. Each point is an institution. The correlation between transparency in 2021 and digital quality in 2026 is positive but weak: 0.32, and 0.17 when discounting the transparency dimension itself.

Institutional websites are today the most frequent gateway to the State. They are consulted for procedures, budgets, scholarships and services, and increasingly they are also being consulted by search engines and artificial intelligence-based assistants. Despite their importance, Costa Rica did not have a technical evaluation that applied the same instrument, with the same criteria and on the same date, across the entire public sector.

This experiment is not aimed at measuring how good or bad the websites of public institutions are, but rather to test how prepared they are to face an automated system. Even so, it left us with interesting data.

Between September 14 and 15, 2026, an artificial intelligence-assisted measurement system visited the sites of 338 public sector institutions according to MIDEPLAN. It evaluated eight dimensions: accessibility, usability, performance, security, domain hygiene, privacy, transparency and digital maturity. The result is a prototype of what could be an Institutional Digital Quality Index (ICDI), a scale from 0 to 100 with fixed criteria, designed to be repeated and measure progress over time.

Of the 276 institutions that could be fully evaluated, none reached the upper band, reserved for scores of 80 or more, and one, the Municipality of San Rafael, reached the second. The national median is 42 points and eight out of ten institutions are in the two lower bands. The figures describe a sector with broad digital presence and considerable room for improvement.

These results must be read with a caveat. They correspond to the automated measurement, without human correction, of what any browser observes. They constitute the first half of an experiment whose second phase will contrast each result with an expert review. The objective is not only to describe the state of public sites, but also to establish which indicators an artificial intelligence-based audit proves reliable for.

A demanding scale by design#

The ICDI does not seek to rate based on average performance. Each indicator is compared against an external standard: WCAG 2.2 accessibility guidelines, recognized performance thresholds for the web, or the obligations established in national regulations (World Wide Web Consortium [W3C], 2023). That decision makes the index demanding, but it also means that results can be compared from one year to the next without reinterpretation.

The second methodological decision is aggregation. The dimensions are combined using a geometric mean, which prevents good performance in speed from compensating for a weakness in accessibility. With a simple average, the national median would go from 42 to 49 points. That difference is not a calculation error, but a measure of the imbalance: most sites combine clear strengths with specific gaps.

By sector, the financial and supervisory sector registers the highest median, with 47.2 points, followed by ministries, with 46.0. Professional associations present the lowest, with 34.8. The ranges, however, overlap in almost all groups: the dispersion within each sector is greater than the difference between sectors, which limits the value of comparisons by institution type.

That overlap suggests that digital quality depends less on the size or legal nature of the institution than on specific management decisions. Within local governments, for example, scores of 65.7 and 27.5 coexist. For public policy, the finding points to improvements being able to come from replicable practices among similar institutions, rather than from structural differences that are difficult to close.

Public higher education is one of the cases that deserves attention. Its six institutions are located in bands D and E, with scores between 31 and 44. The result does not reflect the academic quality or technical capacity of those universities, but concrete aspects of their main portals, such as the accessibility statement, security headers or information on data processing, which admit specific improvements.

Transparency and technical quality: two editions, one moderate signal#

Costa Rica has two reference measurements on the transparency of its public sites, both from the Ombudsman's Office with the CICAP of the University of Costa Rica. The original ITSP series evaluated 255 institutions until 2021, with an average of 38.29 points. In 2025, the Ombudsman's Office applied a renewed methodology on a pilot basis, the ITSP 2.0, to 100 institutions (DHR et al., 2021; DHR & CICAP-UCR, 2025).

The two editions are not interchangeable. ITSP 2.0 organizes the evaluation into four equally weighted dimensions, incorporates the experience of requesting information and includes indicators on accessibility and artificial intelligence. Its 100 institutions were selected by the Ombudsman's Office to represent the diversity of the public sector and the Inter-institutional Transparency Network, so they do not constitute a census. Each edition thus answers a different question.

ITSP 2.0 allows for an almost simultaneous comparison, with a one-year difference. Among the 97 institutions present in both measurements, Spearman's correlation with the 2026 ICDI is 0.25, positive and significant. As the two indices assess transparency and accessibility statement, the ICDI was recalculated without those dimensions. The correlation then drops to 0.14 and ceases to be statistically distinguishable from zero.

The overall result masks differences among types of institutions. Within local governments and the decentralized sector, with 31 institutions each in the sample, the correlation reaches 0.48 and 0.47. When shared dimensions are removed, it stands around 0.35, at the threshold of statistical significance. Among comparable institutions, transparency and technical quality tend to advance together, though moderately.

The 2021 series offers another reading, one of persistence and with a broader sample. Among 233 institutions, the correlation between the ITSP 2021 and the ICDI 2026 is 0.32, and 0.17 without the transparency dimension. In that edition the association was mainly driven by domain hygiene and security; with ITSP 2.0 it concentrates on transparency and, with lesser force, on accessibility and digital maturity, reflecting the shift in the instrument's content.

An additional data point helps interpret the two editions. For the 97 institutions evaluated in 2021 and in 2025, the correlation between their transparency scores is 0.70: those who published well four years ago tend to continue doing so, despite the change in methodology. Transparency behaves as a stable institutional capacity, while the technical quality of sites relates to it only partially.

The quadrants of the crossing with ITSP 2.0 identify distinct trajectories. Twenty institutions combine above-median transparency with below-median technical quality. Among those with the greatest distance are the University of Costa Rica, the Legislative Branch, the Judicial Branch, the Ministry of Labor, and the Municipality of Desamparados, with strengths in information publication that do not yet have a technical equivalent.

The inverse trajectory appears mainly in municipalities. San Carlos, Nicoya, Santa Ana, and San Pablo register above-median technical quality with transparency scores below the median, as do the Central Bank and the National Bank. These cases suggest that both capacities can benefit from coordinated programs, but with differentiated focuses depending on each institution's starting point.

The controls applied to the 1.0 series reinforce this reading. The association with the ITSP 2021 holds within local governments and the decentralized sector, and appears consistently across all its editions between 2016 and 2021. The conclusion supported by both sources is consistent: transparency and technical quality share a management foundation, but do not constitute the same institutional capacity.

Accessibility and privacy: where the gaps concentrate#

Some ICDI indicators correspond to current obligations. Technical guidelines for accessibility in Public Administration establish that each site must publish an accessibility statement with the level achieved, the evaluation date, a contact method, and a description of inaccessible content, with review at least annually (Ministry of Science, Innovation, Technology and Telecommunications [MICITT], 2024).

The measurement identified an accessibility statement in 43 of the 278 sites with evaluated content, 15.5%, with a confidence interval between 11.7% and 20.2%. Of those 43 statements, 29 mention a WCAG level, 27 include a contact method, and 12 record a date. The instrument is recent, from 2024, and the result provides a useful baseline for tracking its adoption.

Automated evaluation with axe detected at least one critical-impact issue in 122 of 270 homepages and contrast problems in 173. These issues especially affect people with low vision or those using screen readers. It should be noted that automated tools identify only part of accessibility problems, so these figures should be interpreted as a floor and not as a complete evaluation.

In privacy, the Law on the Protection of Persons with Respect to the Processing of Their Personal Data establishes that before collecting data, the identity and address of the person responsible for the database must be disclosed (Law No. 8968, 2011, art. 5). The measurement found an identifiable privacy policy in 75 of 278 sites, and in only six of them was the responsible party expressly identified.

This result requires careful interpretation. The system did not verify whether each site collects personal data through forms, so it does not allow concluding individual non-compliance. It does indicate that the information required by law is rarely available visibly. Privacy was also the dimension with the lowest median across all strata, making it a priority and cross-cutting area.

Security: a broad foundation with pending adjustments#

Security fundamentals are widely adopted. Nearly all sites use encrypted connections and 93.8% support TLS 1.3, the most recent version of the protocol. These results reflect significant progress and constitute a solid foundation on which to build. The gaps concentrate on complementary configurations, less visible to users, but relevant for protection against attacks.

Forty-nine servers keep TLS 1.0 enabled, which current standards recommend retiring. On 23 sites, the certificate could not be fully verified, in most cases because the intermediate chain is missing, a configuration adjustment that browsers typically compensate for but other systems do not. These are generally low-cost corrections with a direct effect on service robustness.

Institutional email authentication offers another opportunity for improvement. The DMARC standard allows mail servers to be instructed on how to handle messages that spoof a domain (Kucherawy & Zwicky, 2015). In 97 of the 283 measured domains, the policy is not configured to block or quarantine such messages, which reduces protection against spoofing attempts directed at citizens.

The differences between strata in these practices are statistically significant even after correcting for the number of tests performed. The central government applies DNSSEC to 69% of its domains, compared to 7% of local governments. In HSTS, a protection against connection downgrade attacks, the financial sector reaches 75% and professional associations, 22%. These differences point to where technical support would have the greatest impact.

The limits of automated measurement#

The experiment also revealed aspects about the audit technique itself.Seven institutions use protection services that require human verification for any automated client, and in one additional case the server did not accept connections from the system. For those eight institutions, a researcher completed the verification in their browser and the AI performed the analysis using the same criteria, a procedure documented as a methodological exception.

These protections serve a legitimate security function. At the same time, they raise a consideration for the design of digital services: the same mechanisms that filter malicious traffic can hinder access by search engines, accessibility tools, and AI assistants to public information. Finding configurations that balance both objectives is a technical challenge shared by many public administrations.

During the first measurement, an error in the system itself was also detected. The automated browser identified itself in a way that several firewalls interpreted as unwanted traffic, and in about thirty institutions the tool evaluated the verification page instead of the site.The error was identified by reviewing the raw evidence, corrected, and the measurement was repeated in full before calculating the results.

This episode illustrates why the experiment includes a human review phase. An automated audit can produce data with an appearance of precision that, without verification, would lead to incorrect conclusions. Subsequent verification will allow quantifying this type of deviations and determining which indicators automation is sufficiently reliable for and which require expert support.

The relationship of public sites with artificial intelligence#

The National Code of Digital Technologies recognizes the right of people to know when they interact with an artificial intelligence system (Executive Decree N.° 44507-MICITT, 2024). The measurement explored how public sites position themselves with respect to these technologies. Of 283 sites, 161 do not include instructions for AI crawlers in their robots.txt file and 74 do not have that file.

Forty-seven institutions restrict some AI crawler, one authorizes it explicitly, and two publish a file designed to guide language models. These results describe an early stage, in which most institutions have yet to define a stance. They constitute, therefore, a timely baseline for observing how these decisions evolve in the coming years.

As for conversational channels, the system identified 57 sites with this type of service, of which 52 correspond to instant messaging links. No labels for AI-generated content were observed, although this does not imply non-compliance: the obligation applies when content generated by these tools exists, something that cannot be determined from outside the site.

Scope and next steps#

Every automated measurement has limits that are worth explaining. Accessibility tools detect only part of the barriers that an expert evaluation would identify. Security is assessed by observable configuration, not by the absence of vulnerabilities. Performance comes from laboratory conditions. For this reason, the ICDI should be understood as a diagnostic and monitoring instrument, not as a compliance certification.

The study also distinguishes between types of gaps. The accessibility statement and the identification of the data manager correspond to current obligations. Email authentication or DNSSEC are technical best practices without a specific obligation. No result from the index is related to Law 10946, which regulates e-commerce between individuals and not institutional sites.

Coverage also has limits. Of 338 institutions, 55 do not have a measurable website and seven could not be classified due to temporary unavailability during the measurement. Three institutions whose robots.txt file restricts automated access were evaluated by the study's express decision, given their institutional nature. The methodology, code, and data are available to verify each result.

The next phase will contrast these results with human review. That comparison will make it possible to establish the extent to which an AI-based audit can support periodic monitoring of the State's digital quality. If the accuracy proves sufficient, the country would have a low-cost tool to support continuous improvement of its digital services and measure their evolution year by year.


Declaration of interests: the author directs the Directorate for Research, Development and Innovation at MICITT, an institution that issued the accessibility guidelines that this study uses as criteria and that is part of the evaluated universe. The measurement was made with fixed and public criteria, applied equally to all 338 institutions, and both the methodology and data are published so that anyone can review them. This is an exercise conducted in a personal capacity and is not related to their functions, so their opinions or statements do not necessarily represent MICITT's position.

Note. This evaluation was performed by an agentic artificial intelligence system without human validation of its individual results. The scores reflect what the system observed in an automated manner and may contain interpretation errors. The second phase of the experiment will contrast these results with expert review.


Methodological note#

The ICDI 2026 evaluated 283 institutional websites through passive collection: HTTP headers, TLS protocol, public DNS records, published content, accessibility with axe-core 4.13.0, and performance with Lighthouse 13.4.1. Dimensions are normalized against fixed criteria, aggregated using weighted geometric mean, and require at least 75% of the evaluable weight to calculate the index. Proportions include Wilson intervals and contrasts use Bonferroni correction. Cross-references use the ITSP 2021 (series 1.0, 233 paired institutions) and the 2025 ITSP 2.0 (pilot application, 97 of its 100 paired institutions), with lexical matching and manual confirmation of doubtful cases. The full methodology is published at https://github.com/avaloselizondo8/icdi-metodologia.

Interactive data and charts#

ExplorerComparador de instituciones

Busca una institución por su nombre, filtra por estrato y por vía de medición, y compara varias a la vez. Cada punto se selecciona con un clic; con Mayúsculas se añade a la comparación y con doble clic se limpia. Arranca con la Municipalidad de San Rafael, el Poder Judicial y la UCR. Los datos por institución están en el repositorio de la metodología.

Loading the explorer…

References#

Caja de Arena. (2026). Methodology of the Institutional Digital Quality Index (ICDI) 2026. https://github.com/avaloselizondo8/icdi-metodologia

Executive Decree No. 44507-MICITT. (2024). Officialization of the National Code for Digital Technologies. La Gaceta.

Office of the Ombudsman of the Republic, Research and Training Center in Public Administration at the University of Costa Rica & Digital Government. (2021). Transparency Index of the Costa Rican Public Sector 2021: results

Office of the Ombudsman of the Republic & Research and Training Center in Public Administration at the University of Costa Rica. (2025). Final report: pilot application of the Costa Rican Public Sector Transparency Index 2.0 [Report and database]. Funded by the United Nations Office on Drugs and Crime.

Kucherawy, M., & Zwicky, E. (2015). Domain-based Message Authentication, Reporting, and Conformance (DMARC) (RFC 7489). Internet Engineering Task Force. https://doi.org/10.17487/RFC7489

Law No. 8968. (2011). Law for the Protection of Persons Regarding the Processing of Their Personal Data. Legislative Assembly of the Republic of Costa Rica.

Ministry of Science, Innovation, Technology and Telecommunications. (2024). Guidelines for the accessibility of websites and applications in the public sector (MICITT-DGDCFD-PR-001-2024).

World Wide Web Consortium. (2023). Web Content Accessibility Guidelines (WCAG) 2.2. https://www.w3.org/TR/WCAG22/

Technical details

Experiment
CA-002
Type
Experiment
Status
Running
Updated
Reading
16 min
Models
Claude Fable 5.1 (claude-fable-5-1) · Claude Opus 5 (claude-opus-5)
Result
National median of 42 out of 100 and no institution in the upper band. Gaps are concentrated in accessibility and privacy.
Share