TL;DR: The new US AI and Cyber Executive Order focuses on software supply chain security, AI-generated code, secure system design, and vulnerability management, according to Lasso Security. The policy signal is clear: AI adoption now has governance consequences for IAM, NHI, and security teams, not just application owners.
Editorial analysis by NHI Mgmt Group, based on content published by Lasso Security: “Lasso's Commitment to a Secure AI-Driven Future: Embracing the New Cyber Executive Order”.
Key questions
Q: How should security teams govern AI-generated code in production pipelines?
A: Security teams should treat AI-generated code as a controlled identity event, not just a development artifact.
Q: Why do AI tools create new identity governance risks for IAM teams?
A: AI tools create new identity governance risks because they combine fast adoption with broad access paths and subordinate permission objects.
Q: What are the signs that an AI security programme is too fragmented to govern well?
A: A fragmented AI security programme usually shows up as shadow AI, undocumented model lineage, inconsistent ownership, and ad hoc testing.
Practitioner guidance
- Define AI control ownership across security and engineering Assign accountable owners for AI-assisted development, model integrations, and AI-enabled automation so provenance, access, and remediation do not sit with different teams.
- Inventory AI-generated code and model dependencies Track where AI contributes to code, configuration, or operational decisions, and record the pipelines and services those artefacts depend on.
- Extend vulnerability workflows to AI-specific failure modes Add prompt injection, model tampering, and insecure integration paths to existing vulnerability intake, triage, and remediation processes.
Bottom line: AI adoption now creates governance obligations across software supply chain security, identity scope, and vulnerability management, not just model selection.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
AI regulation is now an identity governance problem, not just a policy problem. The executive order’s focus on AI cyber defence, secure AI design, and AI software vulnerabilities shows that governance has moved upstream into the identity layer. Once AI systems are involved in code generation or defensive automation, access, approval, and accountability can no longer be treated as purely human-centred controls. Practitioners should read this as a mandate to reassess which identities are allowed to influence software and security decisions.
A few things that frame the scale:
- 24,008 unique secrets were exposed in MCP configuration files in 2025 alone, the protocol's first year of widespread adoption, according to The State of Secrets Sprawl 2026.
- AI-related credential leaks surged 81.5% year-over-year in 2025, with the surrounding AI infrastructure leaking 5x faster than core LLM providers.
A question worth separating out:
Q: How can teams tell whether AI security controls are actually working?
A: Look for evidence that AI-assisted workflows still preserve named owners, documented approval boundaries, and verifiable review of secrets and code changes. If you cannot trace who approved what, or where AI influence ended, the control is not working. Effective governance leaves an audit trail that matches the real decision path.
👉 Read our full editorial: AI cyber executive order raises the bar for AI and identity governance
AI cyber policy is becoming identity policy by another name: once AI contributes code, makes recommendations, or touches operational workflows, governance can no longer stop at the application layer. The control question becomes who or what is acting, what it can reach, and how those actions are evidenced. Practitioners should treat AI governance as an identity and authorisation problem, not a standalone innovation program.
A few things that frame the scale:
- 92% of organisations expose NHIs to third parties, raising concerns about supply chain security, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: What should security teams prioritise first when AI is entering regulated workflows?
A: They should prioritise trust boundaries, because regulated workflows fail fastest when provenance, access scope, and audit evidence are unclear. The first question is not whether AI can be used, but whether the organisation can prove what the system did, what it accessed, and who remained accountable.
👉 Read our full editorial: AI cyber executive order raises the bar for AI and identity governance