Two Orders, One Mandate: Securing Data for the AI and Post-Quantum Era

From IC Insider Thales Trusted Cyber Technologies

By Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies

In June 2026, the White House issued two executive orders within weeks of each other. Together they leave little doubt about where federal data protection priorities are headed.

On June 5, the administration issued Executive Order 14409, “Promoting Advanced Artificial Intelligence Innovation and Security.” Then, on June 22, 2026, it issued Executive Order 14412 (EO 14412), “Securing the Nation Against Advanced Cryptographic Attacks.” Both orders carried near-term deadlines: EO 14409 expected agencies to at least begin a framework for fulfilling its requirements by early July, while EO 14412 required agencies to appoint a PQC Migration Lead by late July.

Though the two orders were issued separately, they meet at the same point: The need to protect data, both at rest and in transit, through a combination of AI-aware safeguards and post-quantum cryptography (PQC). For agencies and the contractors that support them, meeting both orders’ requirements will mean moving on cryptographic modernization more quickly than some might have expected.

EO 14409: Accelerating AI while protecting the data behind it

At its heart, EO 14409 carries with it the expectation that important data at rest and in transit, like what is found in covered frontier models, must be protected through both AI and PQC. The order establishes a federal strategy to accelerate adoption of secure, trustworthy, and responsible AI across government agencies and critical infrastructure sectors. AI systems must be safe, auditable, and resilient while still preserving innovation and competitiveness.

To get there, the order directs federal agencies to implement improved safeguards, promote AI modernization efforts, and protect sensitive datasets. They must also create governance structures for model integrity, provenance, testing, and secure cloud adoption. The order further elevates requirements for zero-trust architectures, cryptographic assurance, and quantum-resilient modernization for federal cybersecurity and AI risk-management frameworks.

There are several aspects of this executive order that are important to understand in the context of cryptography and the protection of data in transit and at rest. First, it clearly increases demand for high-assurance cryptography for AI systems and zero-trust access controls for AI data pipelines. It also elevates the need for secure cloud and hybrid infrastructure to run AI workloads. Most importantly from a security perspective, it drives federal agencies toward quantum-ready cryptographic modernization, requiring protection of training data, models, and system credentials.

The order’s data-security implications are explicitly laid out in Section 4, “Protection Against Criminal Actors.” In that section, the Attorney General is directed to prioritize enforcement of federal criminal laws against using AI to illegally access a federal computer, or to use AI for illegal access while committing any other crime. This definition of “illegal access” extends to breaching public or private information technology systems.

To accomplish the order’s requirements, agencies are expected to work closely with the private sector. By doing so, they can be more confident government and private-sector information systems can be modernized and hardened against external threats while cultivating America’s advanced AI-enabled capabilities.

The order specifically calls out eight requirement areas agencies and their vendors should be prepared to address:

  • Secure AI Training Data: Provide encryption, access control, and protection from data poisoning;
  • Protect AI Models: Prevent model theft and ensure controlled access;
  • Authentication and Identity: Establish zero-trust identity for model operators and services;
  • Model Integrity and Provenance: Ensure verification of both lineage and authenticity;
  • Secure Cloud AI Workloads: Create compliant, secure cloud operations for AI;
  • Auditability and Monitoring: Log and monitor AI data and model access;
  • Quantum-Ready Modernization: Ensure modernization efforts are aligned with PQC expectations; and
  • AI Red-Teaming and Testing: Develop secure environments for testing and evaluation

 

Many of these requirements may be beyond the in-house capabilities of many affected agencies. That is a primary motivator for EO 14409’s underscoring of collaboration with the private sector.

As progress continues in the disruptive fields of AI and post-quantum cryptography, one is balanced against the other. Increased popularity of one technology carries with it a need to accelerate adoption of the other. EO 14409 ensures that AI innovations can continue to improve service to American citizens, and progress doesn’t come at the cost of misuse of data that could undermine the security of the nation’s IT infrastructure.

EO 14412: A call to arms on quantum-resistant cryptography

Where EO 14409 addresses AI, EO 14412 addresses the cryptography underneath it — with considerable force.

As Section 1 of the order explains, bad actors with large-scale quantum computers pose a significant threat to widely used cryptographic security systems. The real risk is that adversaries are now harvesting highly sensitive, long-lived data now, including classified information, Personally Identifiable Information (PII), medical records, and trade secrets. Their intent to decrypt that data comes later,  once cryptographically relevant quantum computers (QRQC) become operational (a tipping point that could break today’s Public Key Infrastructure [PKI]). EO 14412 is a call to action for federal agencies to start planning the transition of federal information systems to quantum-safe, NIST FIPS-approved algorithms for post-quantum cryptography.

This order essentially ushers in the greatest cryptographic migration in recent memory. Rightly so. Unlike previous guidance-based PQC policy, EO 14412 has teeth, with enforceable requirements for nearly all federal systems. Earlier guidance applied to narrower groups, including the intelligence community and national security systems. This order covers all federal agencies. It addresses “harvest now, decrypt later” threats directly, accelerates key-establishment and digital-signature migration timelines, and extends compliance obligations to federal contractors. It also mandates that agencies appoint a dedicated PQC Migration Lead.

It’s not overstating matters to say that implementing post-quantum cryptography will help ensure that we are all able to maintain our way of life in the Internet Age. A significant part of this transition is ensuring that PQC solutions are crypto agile, enabling a smooth transition now and as algorithms continue to evolve.

The order’s key deadlines are:

  • Appoint a PQC Migration Lead: late July 2026
  • Complete NIST-led pilot migration: December 31, 2027
  • Transition key-establishment protocols to PQC: December 31, 2030
  • Transition digital signatures to PQC: December 31, 2031
  • Federal contractor PQC readiness: end of 2030

 

What IC organizations should do now

With impending deadlines from both orders, agencies and their contractors have concrete, near-term work to do. Both orders point to largely the same set of actions.

Begin with assessment and inventory. EO 14412 compliance starts with a PQC risk assessment to identify an organization’s “high value assets” and high-impact systems. This is followed by a crypto inventory to determine where cryptography is already in use. Several crypto discovery tools on the market can help automate this process, though crypto discovery should be treated as an ongoing activity, because new cryptography is constantly being created.

Set up a dedicated test environment for PQC migration. Doing so ensures that ongoing operations aren’t interrupted, and prioritize high value assets and high-impact systems for testing before transitioning them to quantum-safe algorithms.

Remain flexible and choose crypto-agile solutions. NIST standardized three PQC algorithms in 2024, two more are being finalized, and another nine for digital signatures are under evaluation. That means the algorithm landscape isn’t finished settling.

On the vendor side, both orders point to a similar set of must-have capabilities:

Agencies and vendors should begin post-quantum cryptography implementation and hybrid PQC transitions now. Hardware security modules deserve particular attention. They are among the best solutions for protecting AI credentials, signing keys, and model integrity, and for enforcing secure access. Under EO 14412 they should also be FIPS 140-compliant and capable of generating quantum-enhanced keys, ideally using an embedded QRNG chip for high-quality, quantum-based entropy.

Develop data security platforms to encrypt and govern AI training data and sensitive model outputs. Confidential computing integrations will be essential to protect model inference and training from manipulation or unauthorized access. Hardware overall should be hardened and tamper-resistant to support government requirements from the core to the cloud to the edge, for data at rest and in motion.

Improve identity and access management. Solutions should rely on smart cards and tokens, including Common Access Card (CAC), Personal Identity Verification (PIV), and Fast Identity Online (FIDO) , to enable phishing-resistant multi-factor authentication.

Together, EO 14409 and EO 14412 make it clear that AI adoption and post-quantum cryptographic migration are no longer separate initiatives on separate timelines. They are converging requirements with real deadlines this year and next. EO 14412, in particular, is the most significant cryptographic policy directive issued in decades. This order recognizes that protecting federal systems against quantum-era threats requires action now, before those threats are fully realized.

The agencies and contractors that begin this work in earnest today — assessing risk, inventorying cryptography, and adopting crypto-agile, AI-ready security infrastructure — will be far better positioned when the deadlines in both orders arrive.

About Thales TCT

Thales Trusted Cyber Technologies, a business area of Thales Defense & Security, Inc., protects the most vital data from the core to the cloud to the field. We serve as a trusted, U.S. based source for cyber security solutions for the U.S. Federal Government. Our solutions enable agencies to deploy a holistic data protection ecosystem where data and cryptographic keys are secured and managed, and access and distribution are controlled.

For more information, visit www.thalestct.com

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.