Today, at ServiceNow’s annual customer and partner event, Knowledge 2026, ServiceNow launched Autonomous Security & Risk to govern every AI agent, identity, and connected asset. Armis delivers continuous asset intelligence across code, IT, OT, IoT, and connected assets. Veza provides fine-grained visibility, intelligence, and governance for human and non-human identities. The result of this combination is one of the most complete security, risk, and compliance platforms in enterprise AI.
Security and risk crossed $1 billion in annual contract value (ACV) for ServiceNow last year, making it one of the fastest-growing sources of demand on the ServiceNow AI Platform. The pressure is compounding as AI exponentially multiplies identities, permissions, connected assets, and decisions that require governance. AI agents acquire access, execute decisions, and operate at machine speed – and the non-human identities behind them already vastly outnumber human ones. Who approved that access, why it exists, and whether it remains valid are questions most enterprises cannot answer. Disconnected security tools cannot close this gap; a platform approach can.
Every AI agent is an identity, with most ungoverned
Every AI agent that acts inside an enterprise does so through an identity. It accesses systems, reads data, and executes workflows under a set of permissions that were almost certainly designed for human actors, rather than the speed, scale, or autonomy of AI agents. Closing the identity visibility, intelligence, and governance gap is critical.
Veza’s Access Graph provides a continuous, real-time map of every access relationship across an enterprise environment, including what has access, what it can do with that access, and how these change as context shifts, systems evolve, and agents multiply. With Veza now integrated into the ServiceNow AI Platform, this capability governs both human and non-human identities within a single operational framework: surfacing risk, enforcing least privilege at the point of action, triggering downstream remediation, and building the traceable institutional memory that auditors and regulators require. ServiceNow Veza works in concert with ServiceNow’s existing vulnerability, exposure, and incident management capabilities to close pre-breach & post-breach exposure: governing who and what has access and continuously identifying and remediating permission-related vulnerabilities.
You cannot secure what you cannot see
Asset visibility has always been a foundational requirement of enterprise security, along with a persistent failure point. The environments enterprises operate in today span pre-compiled code, IT infrastructure, operational technology, connected devices, cloud workloads, medical equipment, and now AI agents, interacting across boundaries that no single tool was ever meant to fully see.
Once integrated into ServiceNow, Armis will deliver real-time, contextual awareness of every connected cyber asset, including the devices and systems conventional tools had no visibility into. Armis will monitor network traffic without agents, without disrupting operations, and enrich every asset record with device type, classification, firmware version, behavioral data, and real-time risk posture. This intelligence flows directly into the ServiceNow CMDB, turning a hitherto static inventory into a live picture of the actual attack surface. When an asset is found to be vulnerable, misconfigured, or behaving anomalously, ServiceNow responds at machine speed, in accordance with prevalent environmental context.
Together, Veza and Armis boost ServiceNow’s standing as a platform that knows what exists in the environment and who or what is permitted to interact with it. This real-time asset intelligence feeds directly into ServiceNow’s security incident response workflows, so the same context used to assess risk before a breach is immediately available to contain it after.
The blueprint for trusted AI
When AI acts inside an enterprise, it must do so with the full business reality behind every decision, including governed permissions, continuous oversight, and an audit trail that holds under scrutiny. That is what Autonomous Security & Risk delivers. Asset intelligence, identity governance, risk management, and workflow automation operating as a single system, with AI running across all of it. Two new AI specialists, announced today as part of ServiceNow’s autonomous workforce expansion, handle vulnerability resolution and security operations end to end, autonomously addressing unresolved vulnerability backlogs and investigating phishing incidents alongside human teams.
The ServiceNow AI Control Tower governs agents, ensuring they are inventoried from the moment they appear, risk-scored continuously, and least privilege enforced in real time. Evaluations score agents as they run. If something drifts, the AI Control Tower is able to catch it before it compounds. A2A and MCP interoperability means any agent, on any platform, operates within a governed framework that connects decisions to context and accountability to action. That same governed framework extends across ServiceNow’s partner ecosystem, so the third-party security tools enterprises already rely on feed into a continuously updated picture of enterprise posture. ServiceNow’s own security operations team runs Autonomous Risk & Security, handling incidents seven times faster than prior workflows using AI agents, with every action documented and every decision traceable.
Organizations are already seeing results on the ServiceNow AI Platform. A global energy company operating across 70+ countries saved 1.2 million hours by automating security operations and cut the time it takes to contain threats by 97%. A major U.S. financial services institution eliminated 96% of dormant non-human identities, turning least privilege from a policy goal into an enforced reality. A Fortune 100 aerospace manufacturer reduced the time to complete control attestations by 75% and close compliance gaps by 85%, replacing manual audit prep with evidence that captures itself.
Enterprises that establish this foundation of complete visibility, governed identities, integrated risk, and autonomous response will be decisively ahead as AI accelerates further. ServiceNow gives security and risk leaders a single view of how exposure, incidents, and identity decisions translate to enterprise risk posture in real time, with the audit trail regulators require.
Related
This entry was posted on May 5, 2026 at 1:02 pm and is filed under Commentary with tags ServiceNow. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
ServiceNow launches Autonomous Security & Risk, integrating Armis and Veza to govern every AI agent, identity, and connected asset
Today, at ServiceNow’s annual customer and partner event, Knowledge 2026, ServiceNow launched Autonomous Security & Risk to govern every AI agent, identity, and connected asset. Armis delivers continuous asset intelligence across code, IT, OT, IoT, and connected assets. Veza provides fine-grained visibility, intelligence, and governance for human and non-human identities. The result of this combination is one of the most complete security, risk, and compliance platforms in enterprise AI.
Security and risk crossed $1 billion in annual contract value (ACV) for ServiceNow last year, making it one of the fastest-growing sources of demand on the ServiceNow AI Platform. The pressure is compounding as AI exponentially multiplies identities, permissions, connected assets, and decisions that require governance. AI agents acquire access, execute decisions, and operate at machine speed – and the non-human identities behind them already vastly outnumber human ones. Who approved that access, why it exists, and whether it remains valid are questions most enterprises cannot answer. Disconnected security tools cannot close this gap; a platform approach can.
Every AI agent is an identity, with most ungoverned
Every AI agent that acts inside an enterprise does so through an identity. It accesses systems, reads data, and executes workflows under a set of permissions that were almost certainly designed for human actors, rather than the speed, scale, or autonomy of AI agents. Closing the identity visibility, intelligence, and governance gap is critical.
Veza’s Access Graph provides a continuous, real-time map of every access relationship across an enterprise environment, including what has access, what it can do with that access, and how these change as context shifts, systems evolve, and agents multiply. With Veza now integrated into the ServiceNow AI Platform, this capability governs both human and non-human identities within a single operational framework: surfacing risk, enforcing least privilege at the point of action, triggering downstream remediation, and building the traceable institutional memory that auditors and regulators require. ServiceNow Veza works in concert with ServiceNow’s existing vulnerability, exposure, and incident management capabilities to close pre-breach & post-breach exposure: governing who and what has access and continuously identifying and remediating permission-related vulnerabilities.
You cannot secure what you cannot see
Asset visibility has always been a foundational requirement of enterprise security, along with a persistent failure point. The environments enterprises operate in today span pre-compiled code, IT infrastructure, operational technology, connected devices, cloud workloads, medical equipment, and now AI agents, interacting across boundaries that no single tool was ever meant to fully see.
Once integrated into ServiceNow, Armis will deliver real-time, contextual awareness of every connected cyber asset, including the devices and systems conventional tools had no visibility into. Armis will monitor network traffic without agents, without disrupting operations, and enrich every asset record with device type, classification, firmware version, behavioral data, and real-time risk posture. This intelligence flows directly into the ServiceNow CMDB, turning a hitherto static inventory into a live picture of the actual attack surface. When an asset is found to be vulnerable, misconfigured, or behaving anomalously, ServiceNow responds at machine speed, in accordance with prevalent environmental context.
Together, Veza and Armis boost ServiceNow’s standing as a platform that knows what exists in the environment and who or what is permitted to interact with it. This real-time asset intelligence feeds directly into ServiceNow’s security incident response workflows, so the same context used to assess risk before a breach is immediately available to contain it after.
The blueprint for trusted AI
When AI acts inside an enterprise, it must do so with the full business reality behind every decision, including governed permissions, continuous oversight, and an audit trail that holds under scrutiny. That is what Autonomous Security & Risk delivers. Asset intelligence, identity governance, risk management, and workflow automation operating as a single system, with AI running across all of it. Two new AI specialists, announced today as part of ServiceNow’s autonomous workforce expansion, handle vulnerability resolution and security operations end to end, autonomously addressing unresolved vulnerability backlogs and investigating phishing incidents alongside human teams.
The ServiceNow AI Control Tower governs agents, ensuring they are inventoried from the moment they appear, risk-scored continuously, and least privilege enforced in real time. Evaluations score agents as they run. If something drifts, the AI Control Tower is able to catch it before it compounds. A2A and MCP interoperability means any agent, on any platform, operates within a governed framework that connects decisions to context and accountability to action. That same governed framework extends across ServiceNow’s partner ecosystem, so the third-party security tools enterprises already rely on feed into a continuously updated picture of enterprise posture. ServiceNow’s own security operations team runs Autonomous Risk & Security, handling incidents seven times faster than prior workflows using AI agents, with every action documented and every decision traceable.
Organizations are already seeing results on the ServiceNow AI Platform. A global energy company operating across 70+ countries saved 1.2 million hours by automating security operations and cut the time it takes to contain threats by 97%. A major U.S. financial services institution eliminated 96% of dormant non-human identities, turning least privilege from a policy goal into an enforced reality. A Fortune 100 aerospace manufacturer reduced the time to complete control attestations by 75% and close compliance gaps by 85%, replacing manual audit prep with evidence that captures itself.
Enterprises that establish this foundation of complete visibility, governed identities, integrated risk, and autonomous response will be decisively ahead as AI accelerates further. ServiceNow gives security and risk leaders a single view of how exposure, incidents, and identity decisions translate to enterprise risk posture in real time, with the audit trail regulators require.
Share this:
Like this:
Related
This entry was posted on May 5, 2026 at 1:02 pm and is filed under Commentary with tags ServiceNow. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.