Chloe Maraina has spent her career at the intersection of big data and strategic foresight, helping organizations navigate the complex waters of business intelligence and data science. As the landscape of artificial intelligence shifts from experimental toys to critical infrastructure, her role has evolved into that of a central architect for AI governance, ensuring that the integration of frontier models aligns with both security imperatives and ethical standards. This conversation explores the profound implications of the White House Executive Order 14409, issued in June 2026, and how it serves as a catalyst for a more disciplined approach to vendor management. We delve into the mechanics of voluntary benchmarking, the rigorous demands of new state and international laws, and the practical steps leaders must take to ensure their AI supply chain is as resilient as it is innovative.
The conversation centers on the transition of AI due diligence from a bureaucratic hurdle to a strategic necessity, where the focus is no longer just on what a model can do, but how it is governed and secured. We touch upon the significance of the 30-day federal review window for developers, the specific technical risks associated with “advanced cyber capabilities,” and the intricate dance of maintaining compliance across jurisdictions like California, Colorado, and the European Union. Maraina provides a roadmap for procurement teams, emphasizing the need for structured attestations, adversarial red-teaming, and a move away from “black box” implementations toward transparent, accountable AI ecosystems.
How does the June 2026 Executive Order 14409 fundamentally change the way a Chief Information Officer or a procurement leader looks at their AI vendor list?
The issuance of Executive Order 14409 in June 2026 marked a turning point where AI vendor management shifted from being a simple performance evaluation to a national security priority. For a CIO or a procurement leader, the order signals that if a vendor is developing or reselling access to frontier models, their compliance is no longer an optional “nice-to-have” but a core component of due diligence. Even if your organization isn’t a direct federal contractor, you have to ask yourself whether your vendor understands the specific risk class of the models they are handing you. This creates a psychological shift in the boardroom; we are no longer just looking at feature velocity or how fast a tool can summarize a meeting. Instead, we are scrutinizing the vendor’s maturity through the lens of the EO’s cybersecurity premises, forcing us to treat these models with the same gravity as we would a critical piece of infrastructure in a high-stakes energy grid or a financial system.
There is a lot of talk about the 30-day voluntary review window for developers—what does a vendor’s participation in this process actually tell you about their internal operations?
When a developer chooses to provide the federal government with access to a covered frontier model for up to 30 days before its general release, it acts as a massive signal of operational discipline. This window is a high-pressure environment where the vendor must manage confidentiality, intellectual property, and nondisclosure protections while their model weights are under a microscope for potential cyber risks. If a vendor participates, it tells me they have a stable “release candidate” and the confidence to let third-party experts poke around their systems before the public does. It’s a sign that they aren’t just shipping code into the wild and hoping for the best; they have a controlled environment capable of responding to findings during that month-long evaluation. For me, a vendor that avoids this voluntary framework might be hiding a lack of release discipline or, worse, a model that hasn’t been properly hardened against advanced cyber threats.
Section 3 of the Executive Order mentions a classified benchmarking process for “advanced cyber capabilities.” How do we perform due diligence when the actual risk thresholds remain hidden from the public eye?
It is a bit of a paradox to navigate a procurement process where the specific benchmarks used by the Secretary of War or the National Security Agency are classified, but that’s where the human element of governance comes in. Since we cannot see the exact numbers or thresholds, we have to look for the “shadow” of those benchmarks in the vendor’s behavior and their willingness to provide structured attestations. We expect vendors to state clearly whether they participate in the framework and what specific terms of government access apply to their frontier-risk assessments. It forces procurement teams to ask more probing, qualitative questions: Does the model have the autonomy to discover vulnerabilities across systems or chain findings in a way that could be weaponized? By focusing on these “advanced cyber capabilities”—like the ability to generate exploit-relevant code or interact with production terminals without human review—we can gauge the risk even if we don’t have the classified rubric in our hands.
With the introduction of the Gold Eagle initiative, vulnerability management seems to be taking center stage. How should companies weigh a vendor’s security hygiene against the raw power of their AI features?
The Gold Eagle initiative really forces a recalibration of our priorities by placing coordinated vulnerability management on equal footing with model quality. In the past, we might have overlooked a clunky update process if the AI’s output was revolutionary, but those days are over. Now, we evaluate vendors on their vulnerability intake, their customer notification protocols, and how they protect sensitive information during patch coordination. It’s a sensory experience for a CISO; you want to feel that the vendor has a robust collaboration rhythm with open-source maintainers and critical infrastructure operators. If a vendor is pushing features at a breakneck pace but lacks a clear cadence for patching or protecting model weights, they are essentially shifting a massive amount of hidden risk onto your shoulders. I’ve seen organizations get blinded by “feature velocity,” only to realize later that they’ve integrated a system that can autonomously discover vulnerabilities in their own network.
As we look toward the 2027 enforcement of Colorado’s SB26-189 and the existing requirements of California’s SB 53, how do these state-level mandates complicate the life of a global vendor?
The regulatory landscape is becoming a patchwork of overlapping obligations that can feel like a minefield for any vendor operating across state lines or international borders. Colorado’s revised SB26-189, which becomes effective in January 2027, is particularly demanding because it requires developers to provide documentation on everything from training-data categories to known limitations and intended uses. Then you have California’s SB 53, which adds another layer by requiring frameworks for whistleblower protection and reporting critical safety incidents. A global vendor can’t just rely on a single certification anymore because what satisfies the European Commission’s enforcement in August 2026 might not meet the specific “human review” requirements in a high-impact workflow in Denver. We are seeing a shift where vendors must provide a granular, transparent look into their automated decision-making technology to prove they aren’t creating systemic risks in areas like lending, healthcare, or insurance.
When it comes to the actual Request for Proposal (RFP) process, what are the technical “must-haves” that you believe are now non-negotiable for a modern AI deployment?
The RFP has to evolve from a basic security questionnaire into a deep dive into the model’s DNA and its operational boundaries. I now insist on structured documentation that covers the model family, versioning, tool integrations, and specifically, the points where human review is mandatory versus where the system has “excessive agency.” We also require evidence of vulnerability assessments that specifically look for prompt injection, training data poisoning, and model denial-of-service, all aligned with the NIST AI 600-1 profile. It’s not enough to say you have security; I want to see the audit evidence—SOC 2 Type II, ISO 42001, and summaries of third-party penetration tests. We are also looking for very clear telemetry rules: exactly what data is being used for security monitoring versus what is being siphoned off for “product improvement,” which we strictly prohibit without written consent.
How should a legal team approach the “black box” problem during contract negotiations, especially regarding intellectual property and data ownership?
Contract negotiations for AI are now some of the most intense discussions I participate in because we are fighting to protect the organization’s most valuable prompts and proprietary documents. We have to be incredibly surgical with our language, explicitly prohibiting the use of customer inputs, embeddings, or derived data for training or fine-tuning the vendor’s models without prior consent. On the flip side, vendors are fiercely protective of their model weights and system instructions, so we have to create a “secure review” process that doesn’t accept a black box but respects their trade secrets. We also need to define very specific incident response commitments for things like output-based data leakage or unsafe autonomous behavior. It’s about building a legal “sandbox” where both parties can innovate without fear that a single model update will suddenly expose our source code or customer records to the entire world.
Given that AI risks are constantly evolving, what does “ongoing vendor management” look like after the contract is signed and the system is live?
The “set it and forget it” mentality is a recipe for disaster with frontier AI because a model that was safe in June might become a liability by December after a significant capability jump or a new integration. I recommend a quarterly review cadence where we sit down with material vendors to discuss everything from red-team results to changes in their sub-processor list. We actually run periodic tabletop exercises to simulate what happens if the AI shows “excessive agency” or if there’s a compromise of the model weights. It’s an active, almost rhythmic process of monitoring their participation in federal coordination efforts like Gold Eagle and reassessing our compliance with state and international laws at least twice a year. You have to keep a pulse on the model’s behavior and the vendor’s update controls, ensuring that any material changes to safety filters or logging practices are flagged before they impact your production environment.
What is your forecast for the future of AI procurement and the role of voluntary frameworks in shaping global standards?
I believe we are entering an era of “certified transparency” where the voluntary frameworks we see today, like the ones established in the June 2026 Executive Order, will become the de facto baseline for the entire industry. Within the next two to three years, the distinction between a “frontier model” and a standard enterprise tool will blur, but the rigorous testing and documentation requirements will remain as a permanent fixture. We will see a consolidation of vendors as those who cannot meet the high bar of cybersecurity, auditability, and legal compliance in places like the EU and California are squeezed out of the market. Ultimately, the successful organizations will be those that view these regulations not as a burden, but as a blueprint for building trust. My forecast is that “governance-as-a-feature” will become the most valuable selling point for any AI developer, transforming the way we buy, deploy, and rely on these powerful technologies for decades to come.
