
NEWORDER has partnered with Lasso Security, a Tel Aviv-based AI security company, to bring agentic AI protection to South Africa. The platform lets NEWORDER run continuous adversarial testing against a client’s AI agents — attacking them the way an outsider would, to find where they give way.
An AI agent is not a chatbot that answers questions. It is software that reads a document, decides what it means and then acts: pulls a record, sends a message, updates a system, calls another piece of software. It holds credentials, and it reads whatever it is pointed at. The usual comparison is a junior employee with system access, no training and no judgement — except this one works at machine speed at 3am, with nobody watching.
That same agent takes instructions from anyone who can get text in front of it. A serious flaw found in a major corporate AI assistant last year allowed company data to leave the business through an instruction hidden inside an ordinary incoming e-mail. Nobody clicked anything. Nobody made a mistake.
“Your AI agents take orders from strangers.”
South African organisations have spent two years deploying these agents, and many still cannot say who the agents answer to. “In NEWORDER’s experience, few organisations can produce a list of the agents running in their estate,” says Bennie Barnard, chief commercial officer at NEWORDER. “They arrive through assistant rollouts, developer tools, vendor integrations and ordinary human beings solving real problems with whatever works.”

One contract, one team
NEWORDER, the Pretoria-based tactical managed cybersecurity firm, is Lasso Security’s official partner in South Africa. Local organisations can now reach the platform through NEWORDER: one contract, one commercial relationship, one team doing the deployment.
The platform sits between a company’s AI agents and every business system they touch. It identifies the agents an organisation is running, including the ones nobody registered. It reads each instruction before the agent acts on it and stops the ones that break the rules. It also flags when an agent starts behaving out of pattern.
Lasso Security was founded in Tel Aviv in 2023, is certified to ISO 27001 and SOC 2, and has customers across Europe, the US and Israel.
“We are excited about this partnership,” says Elad Schulman, chief executive and co-founder of Lasso Security. “It strengthens our in-country presence and capabilities in a region moving quickly on AI adoption, and it pairs our research with a team that can act on it locally. Research on its own secures nothing. It has to reach an organisation through people with the expertise to apply it, and that is exactly what NEWORDER brings.”

No AI law – the accountability arrived anyway
In April 2026, the department of communications & digital technologies gazetted a draft national AI policy, then withdrew it 16 days later after journalists found that several of its 67 references were fabricated. The state got to pull the document and start again. A board does not get that option.
“There is no official AI law in South Africa, and there will not be one soon, and that changes nothing,” says Barnard. “King V made the board accountable this financial year. Joint Standard 2 already requires evidence of testing. Popia never stopped applying. The question is not whether you have an AI policy. It is whether you can show, on a date, that somebody tested this and somebody independent checked the result.”
Four instruments already reach these agents. None of them mentions artificial intelligence by name, because none of them needs to.
- King V, the corporate governance code applying to financial years beginning on or after 1 January 2026, holds the governing body accountable for how technology is acquired, developed, used and distributed. It expects human oversight proportionate to risk, and periodic assurance. It is an apply-and-explain code rather than legislation, but it is binding on JSE-listed companies through the listings requirements and is the benchmark against which directors’ duties are read. An organisation that cannot show who oversees an agent, who can stop it and who last checked it does not have a governance story.
- Joint Standard 2 of 2024, the cybersecurity and cyber resilience standard issued by the Prudential Authority and the Financial Sector Conduct Authority, took effect on 1 June 2025 for banks, insurers, asset managers, retirement funds and a wide range of financial service providers. It requires documented evidence of control testing on a maintained calendar, including simulated incidents, and third-party controls equivalent to the institution’s own. An agent that calls tools is a system, and nothing exempts it from the testing calendar.
- Popia did not pause for AI. Section 19 requires safeguards. Sections 20 and 21 cover parties who process on a company’s behalf, and using one does not transfer liability. Section 71 restricts decisions taken solely by automated processing where they significantly affect a person — which is exactly what an agent making a credit or claims decision does.
- The Cybercrimes Act 19 of 2020, section 2, deals with unlawful access. An agent tricked into reaching data outside its authority is that access, whoever or whatever typed the instruction.
Then the deadline nobody legislates. The insurance market has started pricing AI risk explicitly rather than covering it by silence. From January 2026, standard-form generative AI exclusion endorsements became available for commercial general liability cover in the US, and several cyber carriers in the London market have moved towards sublimiting AI-related losses at roughly 10% of policy limits rather than excluding them outright. Neither change binds a South African insurer directly, but London wordings travel, and the renewal is the annual moment where documented AI governance stops being a policy document and becomes a number on a quote.

Unmeasurable assurance is not assurance
The habit in the South African market has been to buy the control and take the supplier’s report at face value. The organisation ends up holding a rating written by the party that sold it the technology.
“We bring this platform into South Africa, and we attack what sits behind it,” Barnard says. “We hand over the attack chain, the raw result and a public standard that neither we nor Lasso controls. Your auditor can repeat every step we took. Unmeasurable assurance is not assurance. It is purely orchestrated marketing.”
Start with the framework, not the supplier
There is a test that costs nothing. The OWASP Top 10 for Agentic Applications 2026, published by the OWASP GenAI Security Project in December 2025, names the ten vectors an attacker can use to turn AI agents against the business running them.
NEWORDER tests against that list rather than against its own methodology, and has documented what each of the ten means under Popia, King V and Joint Standard 2. The mapping is on NEWORDER’s website, free and without registration, at newordergroup.net/services/ai-security/owasp-agentic-top-10.
“Benchmark your organisation against these 10 to work out which ones your estate would fail. Once you have identified them, ask your security team to confirm the organisation is covered. If they can confirm it, you have your assurance at no cost. If they can’t, you know what to do,” Barnard says.
Lasso Security’s agentic AI protection platform is available in South Africa through NEWORDER. More on the platform is at lasso.security. Organisations wanting to talk it through can book a 30-minute conversation on the AI roadmap and where the obligations sit at newordergroup.net. No assessment takes place, and nothing is scoped. NEWORDER is a tactical managed cybersecurity firm certified to ISO/IEC 27001 and ISO 9001. This article is general information and does not constitute legal advice.
- Read more articles by NEWORDER on TechCentral
- This promoted content was paid for by the party concerned


