NEWORDER implements Lasso's AI agent control tools in South Africa
Read more
TechCentral
techcentral.co.za

NEWORDER implements Lasso's AI agent control tools in South Africa

NEWORDER has partnered with Lasso Security, a Finnish company based in Tel Aviv, to provide agent-based AI protection in South Africa. This platform allows NEWORDER to conduct continuous vulnerability testing on client AI agents by simulating attacks from external malicious actors.

An AI agent differs from a chatbot that simply answers questions. It is software capable of analyzing a document, determining its meaning, and then performing actions: extracting records, sending messages, updating systems, or calling other programs. Such agents possess credentials and have access to everything they are directed toward. They can be compared to a junior employee with system access who lacks training and judgment, but this agent operates at machine speed around the clock without supervision.

This same agent executes instructions from anyone who can provide it with text. Last year, a serious flaw in a large corporate AI assistant allowed company data to leave the business via an instruction hidden in a regular incoming email. No one clicked on links, and no one made mistakes.

Benny Barnard, Commercial Director of NEWORDER, notes that South African organizations have been using such agents for two years, and many still cannot accurately say who they report to. He adds: 'In NEWORDER's experience, few organizations can compile a list of agents operating within their infrastructure.' These agents appear through the implementation of assistants, developer tools, supplier integrations, and ordinary people solving real-world tasks.

Contract for one team

NEWORDER, a tactical cybersecurity firm based in Pretoria, is the official partner of Lasso Security in South Africa. Local organizations can now access the platform through NEWORDER, which implies a single contract, unified commercial relations, and the work of one implementation team.

The platform sits between the company's AI agents and all the business systems they connect to. It identifies all running agents, including unregistered ones. The system reads every instruction before the agent begins to act and stops those that violate the rules. Furthermore, it signals any instances of atypical agent behavior.

Lasso Security was founded in Tel Aviv in 2023, certified according to ISO 27001 and SOC 2 standards, and has clients in Europe, the USA, and Israel.

Elad Schulman, CEO and co-founder of Lasso Security, stated: 'We are pleased with this partnership. It strengthens our presence in the country and our capabilities in a region that is rapidly adopting AI, combining our research with a team that can apply it locally. Research alone provides nothing; it must reach organizations through people who have the expertise to apply it, and that is what NEWORDER provides.'

Lack of AI laws, but accountability has emerged

In April 2026, the Ministry of Communications and Digital Technologies published a draft national AI policy, but withdrew it 16 days after journalists discovered that seventy-seven links in the document were fabricated. The government managed to withdraw the document and restart the process, whereas the council does not have such an option.

Barnard argues: 'There is no official AI law in South Africa, and there soon won't be, and that changes nothing. The King V Council has placed responsibility on the board of directors for the current financial year. The Joint Standard 2 already requires proof of testing. The Popia principle continues to apply. The question is not whether you have an AI policy. The question is whether you can point to a specific date when someone tested it and someone independent verified the result.'

Four tools already impact these agents. None of them mention artificial intelligence by name, as it is not required. These include: the King V Corporate Governance Code, which is responsible for the acquisition, development, use, and distribution of technologies; the Joint Standard 2, which requires documented proof of control testing; and the Popia law, which limits decisions made solely by automated data processing; and the Cybercrimes Act of 2019, concerning unauthorized access.

A timeframe not regulated by legislation

The insurance market has begun to clearly assess risks associated with AI instead of covering them in silence. Since January 2026, standard exclusions for generative AI have been available in general liability policies in the US, and several cyber insurers in the London market have started reducing loss limits related to AI to approximately 10% of the policy limit, instead of a full exclusion.

These changes do not directly obligate South African insurance companies, but the formulations from London are spreading, and the annual renewal period becomes the moment when AI documentation management ceases to be just a document and turns into a figure in the calculation.

An unmeasurable guarantee is not a guarantee. The custom in the South African market was to purchase control and take the supplier's report at face value. As a result, the organization receives a rating compiled by the party that sold it the technology.

Barnard emphasizes: 'We bring this platform to South Africa, and we attack what is behind it. We pass on the attack chain, the raw result, and a public standard that neither we nor Lasso control. Your auditor can replicate every step of ours. An unmeasurable guarantee is not a guarantee. It is purely staged marketing.'

Start with the framework, not the vendor. There is a free test: OWASP Top 10 for Agent Applications 2026, published by the OWASP GenAI Security Project in December 2025, lists ten vectors that an attacker can use to turn AI agents against a business. NEWORDER tests against this list, not its own methodology, and has documented the significance of each of the ten points in the context of Popia, King V, and Joint Standard 2. This map is available on the NEWORDER website for free and without registration.

Barnard advises: 'Benchmark your organization against these 10 points to find out which ones your infrastructure will fail. Once you have identified them, ask your security department to confirm that the organization is protected. If they can confirm it, you get your guarantee for free. If not, you know what to do.'

Lasso Security's AI agent protection platform is available in South Africa through NEWORDER. Further information about the platform can be found on lasso.security. Organizations wishing to discuss it can sign up for a 30-minute conversation about the AI roadmap and obligations at newordergroup.net. No assessment is conducted, and the scope of work is not defined. NEWORDER is a tactical cybersecurity firm certified by ISO/IEC 27001 and ISO 9001. This article contains general information and is not legal advice.

Similar stories

South Africa Maintains Neutrality on Artificial Intelligence Issues, Does Not Join American Pax Silica Alliance
Read more
techcentral.co.za

South Africa Maintains Neutrality on Artificial Intelligence Issues, Does Not Join American Pax Silica Alliance

South Africa's Minister of Communications, Sulli Malatsi, told TechCentral that South Africa has not yet been invited to join Pax Silica—an American pact that draws a line in the global AI supply chain. Furthermore, no African country has signed this document.

The Pax Silica Declaration is a key initiative of the US Department of State regarding supply chain and AI security. It was signed in Washington on December 12, 2025, and now includes 24 signatories after the second summit in June, with Taiwan participating as a 'non-signatory participant.' Participants include manufacturers of critical chips, mineral extractors, and capital markets, including Japan, the EU, the UK, Germany, India, the UAE, and Israel.

Emphasizing the importance of computing power and the minerals that fuel it, U.S. Deputy Secretary of State for Economic Growth, Energy, and Environment Jacob Helberg stated on the Pax Silica website that the declaration ensures that coordinated partners will build the future AI ecosystem, encompassing energy, critical minerals, high-tech manufacturing, and models.

Responding to TechCentral, Malatsi declined to confirm any specific position from Pretoria. He stated that if they are asked to consider joining any multilateral pact or cooperation, they will review the request based on its merits and through proper diplomatic procedures.

When asked which ministry guides the government's position and whether Pax Silica was discussed at the cabinet level, he remained noncommittal: 'If we are approached, we will review the request and its delegation at the appropriate level.'

What Lies Beyond Pretoria

Although the text of the pact is not binding, it carries significant weight because it unites three elements essential for AI development: semiconductors, energy, and the recycling of critical minerals. In March, the US Department of State announced plans to allocate $250 million through Congressional work to a fund dedicated to the mining and processing of critical minerals.

This should be a concern for Pretoria. According to the U.S. Geological Survey, South Africa mines about 70% of the world's platinum and approximately 38% of manganese, yet it remains outside the mechanism that determines where investments, licensing, and procurement related to these minerals will be directed.

Malatsi remains steadfast, asserting that investments from global technology companies and South Africa's existing partnerships 'demonstrate confidence in our current strategies' of neutrality and assessment of multilateral agreements on their substance.

When asked how neutrality ensures access to advanced chips if that access is facilitated through trusted partner mechanisms and export licensing, in which South Africa does not participate, he firmly replied: 'Neutrality allows us to consider all issues without geopolitical barriers,' adding that the government will continue to strive to maintain access to the best available technologies.

A leaked draft letter from the US Department of State warns 35 countries that have signed a separate American declaration—the Joint Statement on AI Opportunities—not to join Beijing's competing bloc. South Africa is not on this list.

The American declaration states: 'Being part of everything means being part of nothing.' An American official explained this more directly to Reuters: 'You cannot have both.'

Pretoria is a founder of the China Association for Artificial Intelligence Cooperation (Waico), which the US calls a 'duplicative initiative' that cannot coexist with Pax Silica. Malatsi previously told TechCentral that Waico carries no obligations, and that South Africa 'is not choosing a side.' Kazakhstan is currently the only known country belonging to both blocs, and it has faced criticism from America for this.

Approximately 10 out of 29 Waico founders are African, while no African country has signed Pax Silica. The continent is well represented in one bloc and entirely absent from the other.

The Right to Choose

China has opposed pressure demanding a choice. Chinese Foreign Ministry spokesperson Li Jian stated on August 19 that China 'firmly opposes taking sides and confrontation by camps' in the field of AI, and that 'all countries have the right to choose their cooperation partners in accordance with their national conditions and development needs.'

[

Popular