Executive Order 14110 on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence was signed in October 2023. It directs federal agencies to establish requirements for organizations developing or deploying AI systems in government contracting, critical infrastructure, and regulated sectors. Unlike voluntary guidance, these requirements will become contractual obligations and regulatory expectations with specific timelines.
The order does not create a single compliance regime. Instead, it instructs agencies to issue sector-specific rules within their jurisdictions. Contractors and regulated entities will face obligations they must meet to maintain eligibility for federal work or to operate within regulatory expectations.
What the Order Directs Agencies to Require
Executive Order 14110 mandates that agencies establish requirements in several areas. Developers of certain AI systems must share safety test results and information about system performance with the federal government. Agencies are directed to create standards for AI use in critical infrastructure sectors, including energy, transportation, and healthcare.
The order explicitly addresses AI systems that could pose risks to national security, economic security, or public health. Organizations working with such systems face the most immediate compliance expectations. Agencies are also directed to establish guidance on the use of AI in their own operations, which will set expectations for contractors supporting those functions.
Federal procurement rules will incorporate requirements for vendors using AI in the delivery of government services. Regulated entities in sectors overseen by agencies such as the Department of Health and Human Services, the Department of Transportation, and the Department of Energy should expect sector-specific requirements tied to AI deployment in their operations.
Why This Matters to Your Business
The business consequence is straightforward: failure to demonstrate compliance will result in contract ineligibility, regulatory findings, or exclusion from federal programs. Unlike cybersecurity frameworks that are widely adopted as voluntary standards, AI requirements under this order will be mandatory for organizations within scope.
Organizations that have built cybersecurity programs around the [NIST Cybersecurity Framework](https://www.nist.gov/cyberframework) will recognise a similar structure, but AI governance introduces new categories of risk. These include algorithmic bias, data lineage, model transparency, and third-party AI services embedded in your operations without formal oversight.
The timeline is compressed. Agencies have been directed to issue initial guidance within months of the order's signing. Some have already done so. Organizations that treat this as a future obligation will find themselves behind when agency-specific requirements become enforceable.
The Accountability Gap
The most common failure pattern is not technical. It is the absence of executive ownership. AI governance sits uncomfortably between IT, legal, compliance, and business units. IT teams can describe the systems in use. Legal can interpret regulatory language. Compliance can track deadlines. But none of these groups is positioned to make the risk decisions, establish the governance framework, or attest to the board that the organization's position is defensible.
Federal agencies will not accept explanations of shared responsibility when a requirement is unmet. They will ask: who is accountable for your organization's AI governance posture? What controls are in place? How do you know they are working? These are executive questions, and they require an executive owner.
Adequate ownership looks like a named individual with authority to make decisions about AI system deployment, the ability to say no to a business unit, and a direct reporting line to the CEO or board for material AI risks. That individual must be able to describe the organization's AI inventory, the rationale for accepting or mitigating each identified risk, and the evidence that supports compliance.
How This Relates to AI and Emerging Technology Governance
AI governance is a subset of emerging technology governance, but it has rapidly become the most urgent. The NIST Privacy Framework and the NIST Cybersecurity Framework both provide structure for managing risks from data and systems. AI governance requires the integration of both, along with additional considerations that neither framework fully addresses.
Organizations subject to the FTC Act, COPPA, the Gramm-Leach-Bliley Act, or sector-specific privacy and security requirements already operate under binding obligations. Executive Order 14110 does not replace those requirements. It adds a new dimension. AI systems that process personal information must comply with existing privacy rules, but they also introduce new risks: automated decision-making that affects individuals, algorithmic outputs that are difficult to explain, and dependencies on third-party models whose behaviour may change without notice.
Emerging technology governance is the practice of establishing decision rights, risk tolerances, and oversight mechanisms before deploying a new capability. For AI, this means understanding where systems are in use, what data they consume, what decisions they influence, and what happens when they produce an unexpected result. Organizations that have treated AI as an IT implementation question will need to reframe it as a governance question.
What Leadership Should Do Next
The first step is to establish accountability. Designate an executive owner for AI governance. This may be a chief information security officer, a chief risk officer, or another senior leader with the authority and position to enforce decisions across the organization. Make it clear that this person is responsible for the organization's compliance position.
The second step is to inventory AI systems. This includes systems you develop, systems you deploy, and third-party services that incorporate AI in ways that affect your operations or your customers. Many organizations discover that AI is far more prevalent than they assumed, embedded in software-as-a-service platforms, customer service tools, and operational analytics.
The third step is to assess which agency-specific requirements apply. If you are a federal contractor, review the agencies you contract with and identify what AI-related requirements they have issued or proposed. If you are a regulated entity, determine whether your regulator has issued guidance under the authority of Executive Order 14110. If you operate in critical infrastructure, expect requirements even if you do not contract with the federal government.
The fourth step is to map your current controls to the anticipated requirements. Use the NIST Cybersecurity Framework and NIST Privacy Framework as reference points. Identify gaps. Document your risk decisions. Build evidence that demonstrates your governance process is functioning.
The fifth step is to prepare for attestation. Federal contractors should expect contract language that requires certification of compliance with AI requirements. Regulated entities should expect examinations or audits that include AI governance. The burden of proof will be on your organization.
The Role of Strategy-First Leadership
Organizations that lack a chief information security officer or equivalent executive often find that regulatory obligations are managed reactively, without a coherent strategy. This creates two problems. The first is inefficiency: disconnected efforts across IT, legal, and compliance produce duplicated work and inconsistent positions. The second is accountability: when an agency asks who is responsible, the answer is unclear.
A [virtual CISO (vCISO)](/vciso/) provides the executive ownership that closes this gap. This is not a consultant brought in for a project. It is ongoing leadership accountable for your cybersecurity and governance strategy, regulatory position, and risk decisions. For organizations facing AI requirements under Executive Order 14110, a vCISO establishes the governance framework, coordinates the cross-functional work, and provides the board with a clear compliance position.
This model is appropriate for organizations that need executive-level security and risk leadership but do not require a full-time internal hire. It is particularly relevant when regulatory obligations are expanding faster than internal capacity.
Practical Next Steps
Start with a single conversation. Assemble your general counsel, chief financial officer, head of IT, and compliance leadership. Ask three questions: do we know where AI is used in our operations? Do we have an executive owner for AI governance? Can we demonstrate compliance if an agency asks today?
If the answer to any of those questions is no, you have a decision to make. You can build internal capability, hire an executive, or engage external leadership on a fractional basis. The timeline for agency implementation does not allow for lengthy searches or capability-building projects.
For organizations that need a clear regulatory position, a defined governance structure, and an accountable executive without the overhead of a full-time hire, Heights Consulting Group provides vCISO leadership focused on strategy, governance, and regulatory accountability. If you would benefit from a confidential discussion about your organization's specific requirements, contact Heights to arrange a consultation.
Sources
- Cybersecurity Framework | NIST , www.nist.gov
- Privacy and Security | Federal Trade Commission , www.ftc.gov
- Privacy Framework | NIST , www.nist.gov
Related service: AI and Emerging Technology Governance
Governance for how your organization adopts artificial intelligence: approved uses, data handling boundaries, review before deployment, and accountability for the output.