September Livestream - Vulnerabilities: Gone in 30 Days

What Security Leaders Need to Know about America’s AI Action Plan

Here’s what the new report from the White House means for software supply chain leaders, and how you can get ahead.

Tim Miller

July 30, 2025

The White House released America's AI Action Plan, a 28‑page roadmap for how the United States government wants AI built, shipped, and secured. If you design, ship, or operate software that relies on AI, treat the document as an 18‑month early‑warning system. It is not a regulatory text; it is directional guidance for federal agencies, but history suggests those agencies will lift entire paragraphs from it when they update their rules. While the specifics will come over the coming months, you can get a head start now. 

Your 12‑month action plan

A lot of people treat AI as entirely separate from traditional software. Their compliance efforts, if any, have an entirely different rigor about them, I don't mean different as in better. I mean different as in entirely different. As I talk to folks, a lot of them are not prepared to head in the direction that America’s AI Action Plan calls for.


Thankfully, it’s straightforward to get started if you treat AI models similar to your other software. The best practices for provenance, dependency management, signing, and so on apply to AI models just as much as they do to your SaaS application. The table below has five basic steps you can take to get ready over the next few months.

Next step Why start now
Map every model, dataset and library into your existing SBOM process Auditors will not accept “models are different” as an excuse when secure‑by‑design language turns into policy.
Extend IR runbooks to cover model corruption, prompt leaks and fine‑tuning drift CISA updates are coming; be the team that already rehearsed the scenario.
Join, or prepare to feed, the AI‑ISAC Threat sharing will be a two‑way street. Early participation builds credibility.
Treat any open‑weight model like a third‑party binary: scan, sandbox, sign The supply‑chain lens must widen beyond traditional code.
Pilot your stack in a sandbox program Get free regulatory feedback while competitors are still polishing pitch decks.

How Kusari can help you

The five steps above are a great start to complying with whatever final regulations and policies that come from America’s AI Action Plan. With Kusari’s products built from our deep expertise in software supply chain security, you can be proactive instead of reactive.

  • Kusari Inspector sits in your existing development workflow. It analyzes pull requests and blocks changes that introduce exploitable CVEs or weaken model controls, creating the audit trail CISA now expects.
  • Kusari Platform stores, enriches, and emits SBOMs that include AI artifacts, ready for secure‑by‑design checkpoints. With Kusari Platform, you get a holistic view of your entire portfolio for both traditional and AI applications.

Curious how that bundle looks in practice? Book a short demo and see the workflow end to end.

Like what you read? Share it with others.

Other blog posts 

The latest industry news, interviews, technologies, and resources.

View all posts

Previous

No older posts

Next

No newer posts

Want to learn more about Kusari?

Schedule a Demo
By clicking “Accept”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. View our Privacy Policy for more information.