Start Free Trial
Home/Regulations/EO 14028 — Improving the Nation's Cybersecurity — Regulatory Reference
Regulatory Reference
Public Sector Federal (US) high

EO 14028 — Improving the Nation's Cybersecurity — Regulatory Reference

Zero trust, incident reporting for federal contractors — AutoPIL agent registry and key scoping implement zero-trust data access.

Key Provisions
  • Zero Trust Architecture (NIST SP 800-207) adoption
  • SBOM requirements and software supply chain security
  • Incident reporting and information sharing expectations
  • Subsequent guidance: OMB M-22-09 and CISA Zero Trust Maturity Model
How AutoPIL Enforces It
  • Pre-retrieval enforcement is zero-trust applied to AI agents — no implicit trust based on network location
  • Agent registry implements identity-centric access policy
  • Audit chain supports incident response and lessons learned
Policy EngineAudit LogSensitivity LabelsAgent RegistryAlert RulesKey Scoping
AutoPIL Policy IDs
PS-EO14028-ZT-001Zero-Trust AI Agent Access
PS-EO14028-IR-001Incident Response Evidence Chain
Official Sources

This page is a working reference and not a substitute for qualified legal review. Verify against official sources before use in compliance artifacts.

Frequently Asked Questions
What does EO 14028 require for zero trust architecture?
Executive Order 14028, issued May 2021, directed federal agencies to adopt Zero Trust Architecture as defined in NIST SP 800-207. The core principle is that no user, device, or system — including an AI agent — receives implicit trust based on network location. Access must be continuously verified, least-privilege enforced at every request, and all access decisions logged. OMB Memorandum M-22-09 followed with specific federal agency timelines and maturity targets. For AI agent deployments, this means every retrieval request must be evaluated against an explicit policy before sensitive data is returned — not after it has entered the agent's context.
Does EO 14028 apply to federal contractors and software vendors?
Yes. EO 14028 extends requirements beyond federal agencies to any software vendor or contractor that sells to or operates systems for the federal government. Section 4 specifically addresses software supply chain security, requiring vendors to maintain SBOMs (Software Bills of Materials), attest to secure development practices, and provide incident reporting when breaches occur. Contractors handling government data must also meet zero-trust access control standards and support federal incident response obligations. Companies integrating AI agents into government workflows — including cloud-based or SaaS tools — fall within scope when those tools process federal information or are part of a federal acquisition.
How does AutoPIL help meet EO 14028 zero-trust requirements for AI agents?
AutoPIL implements zero-trust data access at the retrieval layer. Every AI agent request to a data source is evaluated against an explicit policy before any data is returned — no implicit trust based on agent identity, network location, or prior access. The agent registry enforces identity-centric access: each agent is registered with a scoped API key and bound to a specific policy that defines which data sources it may access, at what sensitivity level, and under what conditions. Key scoping (admin/read/evaluate) limits blast radius if a credential is compromised. The tamper-evident audit chain supports incident response by providing a cryptographically verifiable record of every access decision.
What are the incident reporting requirements under EO 14028?
EO 14028 directed CISA to develop standardized playbooks for federal incident response and required agencies and covered contractors to report cybersecurity incidents promptly. The EO did not specify a single numeric reporting window for all incidents — that is governed by sector-specific rules and agency policy — but it directed OMB to standardize federal incident reporting thresholds. For AI systems, incident response now includes demonstrating what data was accessed, by which agent, under which policy, and when. Without a pre-retrieval audit log, organizations cannot reconstruct an AI agent's data access trail during an incident investigation. AutoPIL's cryptographic audit chain provides that evidentiary record with every logged decision.
How does the CISA Zero Trust Maturity Model relate to EO 14028 compliance for AI?
The CISA Zero Trust Maturity Model (ZTMM), updated in 2023, translates EO 14028's zero-trust mandate into five pillars: Identity, Devices, Networks, Applications and Workloads, and Data. AI agents touch at least three of these pillars simultaneously — they carry an identity, make application-layer requests, and access data. ZTMM's Data pillar explicitly requires data access to be governed by policy, logged, and audited. AutoPIL maps directly to this pillar: source registry classifies data at rest, policy engine enforces access rules per-agent, and every decision is written to an immutable audit log. Organizations targeting ZTMM Advanced or Optimal maturity levels for AI workloads can use AutoPIL's policy enforcement records as direct evidence in assessments.
Covered Industries

EO 14028 applies to all federal agencies and the contractors and software vendors that supply or operate systems on their behalf. For AI deployments, it establishes a zero-trust baseline — no agent, service, or system may access government data without continuous policy verification and a tamper-evident record of every decision.

AutoPIL Governance Platform

Enforce this regulation today

AutoPIL intercepts every AI agent data access call, enforces your policy, and writes a tamper-evident audit record — before sensitive data enters the agent context window.

Start Free Trial View All Industries