NEWORDER has partnered with Lasso Security, a Finnish company based in Tel Aviv, to provide agent-based AI protection in South Africa. This platform allows NEWORDER to conduct continuous vulnerability testing on client AI agents by simulating attacks from external malicious actors.
An AI agent differs from a chatbot that simply answers questions. It is software capable of analyzing a document, determining its meaning, and then performing actions: extracting records, sending messages, updating systems, or calling other programs. Such agents possess credentials and have access to everything they are directed toward. They can be compared to a junior employee with system access who lacks training and judgment, but this agent operates at machine speed around the clock without supervision.
This same agent executes instructions from anyone who can provide it with text. Last year, a serious flaw in a large corporate AI assistant allowed company data to leave the business via an instruction hidden in a regular incoming email. No one clicked on links, and no one made mistakes.
Benny Barnard, Commercial Director of NEWORDER, notes that South African organizations have been using such agents for two years, and many still cannot accurately say who they report to. He adds: 'In NEWORDER's experience, few organizations can compile a list of agents operating within their infrastructure.' These agents appear through the implementation of assistants, developer tools, supplier integrations, and ordinary people solving real-world tasks.
Contract for one team
NEWORDER, a tactical cybersecurity firm based in Pretoria, is the official partner of Lasso Security in South Africa. Local organizations can now access the platform through NEWORDER, which implies a single contract, unified commercial relations, and the work of one implementation team.
The platform sits between the company's AI agents and all the business systems they connect to. It identifies all running agents, including unregistered ones. The system reads every instruction before the agent begins to act and stops those that violate the rules. Furthermore, it signals any instances of atypical agent behavior.
Lasso Security was founded in Tel Aviv in 2023, certified according to ISO 27001 and SOC 2 standards, and has clients in Europe, the USA, and Israel.
Elad Schulman, CEO and co-founder of Lasso Security, stated: 'We are pleased with this partnership. It strengthens our presence in the country and our capabilities in a region that is rapidly adopting AI, combining our research with a team that can apply it locally. Research alone provides nothing; it must reach organizations through people who have the expertise to apply it, and that is what NEWORDER provides.'
Lack of AI laws, but accountability has emerged
In April 2026, the Ministry of Communications and Digital Technologies published a draft national AI policy, but withdrew it 16 days after journalists discovered that seventy-seven links in the document were fabricated. The government managed to withdraw the document and restart the process, whereas the council does not have such an option.
Barnard argues: 'There is no official AI law in South Africa, and there soon won't be, and that changes nothing. The King V Council has placed responsibility on the board of directors for the current financial year. The Joint Standard 2 already requires proof of testing. The Popia principle continues to apply. The question is not whether you have an AI policy. The question is whether you can point to a specific date when someone tested it and someone independent verified the result.'
Four tools already impact these agents. None of them mention artificial intelligence by name, as it is not required. These include: the King V Corporate Governance Code, which is responsible for the acquisition, development, use, and distribution of technologies; the Joint Standard 2, which requires documented proof of control testing; and the Popia law, which limits decisions made solely by automated data processing; and the Cybercrimes Act of 2019, concerning unauthorized access.
A timeframe not regulated by legislation
The insurance market has begun to clearly assess risks associated with AI instead of covering them in silence. Since January 2026, standard exclusions for generative AI have been available in general liability policies in the US, and several cyber insurers in the London market have started reducing loss limits related to AI to approximately 10% of the policy limit, instead of a full exclusion.
These changes do not directly obligate South African insurance companies, but the formulations from London are spreading, and the annual renewal period becomes the moment when AI documentation management ceases to be just a document and turns into a figure in the calculation.
An unmeasurable guarantee is not a guarantee. The custom in the South African market was to purchase control and take the supplier's report at face value. As a result, the organization receives a rating compiled by the party that sold it the technology.
Barnard emphasizes: 'We bring this platform to South Africa, and we attack what is behind it. We pass on the attack chain, the raw result, and a public standard that neither we nor Lasso control. Your auditor can replicate every step of ours. An unmeasurable guarantee is not a guarantee. It is purely staged marketing.'
Start with the framework, not the vendor. There is a free test: OWASP Top 10 for Agent Applications 2026, published by the OWASP GenAI Security Project in December 2025, lists ten vectors that an attacker can use to turn AI agents against a business. NEWORDER tests against this list, not its own methodology, and has documented the significance of each of the ten points in the context of Popia, King V, and Joint Standard 2. This map is available on the NEWORDER website for free and without registration.
Barnard advises: 'Benchmark your organization against these 10 points to find out which ones your infrastructure will fail. Once you have identified them, ask your security department to confirm that the organization is protected. If they can confirm it, you get your guarantee for free. If not, you know what to do.'
Lasso Security's AI agent protection platform is available in South Africa through NEWORDER. Further information about the platform can be found on lasso.security. Organizations wishing to discuss it can sign up for a 30-minute conversation about the AI roadmap and obligations at newordergroup.net. No assessment is conducted, and the scope of work is not defined. NEWORDER is a tactical cybersecurity firm certified by ISO/IEC 27001 and ISO 9001. This article contains general information and is not legal advice.

