ServiceNow is accelerating its Autonomous Security vision with six security solutions centered on prevention-first, AI-native defense. New AI Specialists are designed to autonomously handle vulnerabilities and incidents. With this move, the company is firmly positioning itself as a security player for the AI era.
With this announcement, ServiceNow is bundling six solutions into its AI Control Tower. They cover unified exposure management, continuous vulnerability detection, cyber-physical security, identity and access security, agentic incident response, and cyber risk and compliance. The goal is to prevent, contain, and remediate risks at machine speed, even before a threat escalates into a breach.
ServiceNow previously laid the groundwork for the new products with two acquisitions. The company acquired Armis for $7.75 billion to bolster its asset intelligence capabilities and also acquired Veza for identity and access governance. These two acquisitions now form the backbone of the Autonomous Security portfolio.
Central to this is what ServiceNow calls “Shift Zero”: the shift from fragmented, reactive security to prevention embedded at every layer. “As AI exposures compound exponentially, security teams operate on a human clock,” says Yevgeny Dibrov, SVP and GM of cybersecurity and risk at ServiceNow. “Machine identities double every 18 months. Fragmented security tools can’t match the curve AI is creating.”
AI specialists take over tasks
Specifically, ServiceNow is introducing AI Specialists that autonomously complete security workflows. The Vulnerability Resolution AI Specialist orchestrates triage and remediation, applies low-risk patches, and clears backlogs. A Tier 2 SOC AI Specialist builds multi-phase response plans for complex incidents and escalates only high-risk decisions to human analysts.
AI Agent Access Security and Non-Human Identity Remediation focus on the uncontrolled army of service accounts, cloud identities, and AI agents. Additionally, Cryptographic Asset Compliance maps out migration to quantum-resistant standards.
A large portion is already available, including Agentic Exposure Management, Application Security, DAST, External Attack Surface Management, Agentic AI for Cyber-Physical Security, and the identity solutions. The Tier 2 SOC AI Specialist, Vulnerability Resolution AI Specialist, Agentic AI for Continuous Control Monitoring, and Cryptographic Asset Compliance are expected to follow in December 2026.