ServiceNow launches Autonomous Security & Risk, integrating Armis and Veza to govern every AI agent, identity, and connected asset.
ServiceNow has launched Autonomous Security & Risk to govern every AI agent, identity, and connected asset. As per the announcement, Armis delivers continuous asset intelligence across code, IT, OT, IoT, and connected assets. Veza provides fine-grained visibility, intelligence, and governance for human and non-human identities. The result of this combination is one of the most complete security, risk, and compliance platforms in enterprise AI.
Security and risk crossed $1 billion in annual contract value (ACV) for ServiceNow last year, making it one of the fastest-growing sources of demand on the ServiceNow AI Platform. The pressure is compounding as AI exponentially multiplies identities, permissions, connected assets, and decisions that require governance.
AI agents acquire access, execute decisions, and operate at machine speed – and the non-human identities behind them already vastly outnumber human ones. Who approved that access, why it exists, and whether it remains valid are questions most enterprises cannot answer. Disconnected security tools cannot close this gap; a platform approach can.
“Today’s CISOs have to operate at two speeds: neutralizing threats in real time while reporting risk to the board with conviction,” said John Aisien, Senior Vice President and General Manager, Central Product Management, Security & Risk, ServiceNow. “Autonomous Security & Risk replaces that fragmented stack with a single graph that maps every identity, every permission, and every connected asset, so prevention, detection, and response happen at machine speed.”
Autonomous Security & Risk with Veza & Armis
Every AI agent that acts inside an enterprise does so through an identity. It accesses systems, reads data, and executes workflows under a set of permissions that were almost certainly designed for human actors, rather than the speed, scale, or autonomy of AI agents. Closing the identity visibility, intelligence, and governance gap is critical.
According to ServiceNow, Veza’s Access Graph provides a real-time view of access relationships across the enterprise, showing who and what has access and how permissions change over time. Integrated into the ServiceNow AI Platform, it helps govern both human and non-human identities, enforce least-privilege access, support compliance requirements, and identify permission-related risks. ServiceNow says the integration also complements its vulnerability, exposure, and incident management capabilities to help organizations detect and remediate access-related security issues.
Asset Visibility with Armis
Asset visibility has always been a foundational requirement of enterprise security, along with a persistent failure point. The environments enterprises operate in today span pre-compiled code, IT infrastructure, operational technology, connected devices, cloud workloads, medical equipment, and now AI agents, interacting across boundaries that no single tool was ever meant to fully see, says ServiceNow.
Once integrated into ServiceNow, Armis will deliver real-time, contextual awareness of every connected cyber asset, including the devices and systems conventional tools had no visibility into. Armis will monitor network traffic without agents, without disrupting operations, and enrich every asset record with device type, classification, firmware version, behavioral data, and real-time risk posture.
This intelligence flows directly into the ServiceNow CMDB, turning a hitherto static inventory into a live picture of the actual attack surface. When an asset is found to be vulnerable, misconfigured, or behaving anomalously, ServiceNow responds at machine speed, in accordance with prevalent environmental context.
Together, Veza and Armis boost ServiceNow’s standing as a platform that knows what exists in the environment and who or what is permitted to interact with it. This real-time asset intelligence feeds directly into ServiceNow’s security incident response workflows, so the same context used to assess risk before a breach is immediately available to contain it after.
The blueprint for trusted AI
When AI acts inside an enterprise, it must do so with the full business reality behind every decision, including governed permissions, continuous oversight, and an audit trail that holds under scrutiny. That is what Autonomous Security & Risk delivers. Asset intelligence, identity governance, risk management, and workflow automation operating as a single system, with AI running across all of it. Two new AI specialists, announced as part of ServiceNow’s autonomous workforce expansion, handle vulnerability resolution and security operations end to end, autonomously addressing unresolved vulnerability backlogs and investigating phishing incidents alongside human teams.
The ServiceNow AI Control Tower governs agents, ensuring they are inventoried from the moment they appear, risk-scored continuously, and least privilege enforced in real time. Evaluations score agents as they run. If something drifts, the AI Control Tower is able to catch it before it compounds. A2A and MCP interoperability means any agent, on any platform, operates within a governed framework that connects decisions to context and accountability to action.
That same governed framework extends across ServiceNow’s partner ecosystem, so the third-party security tools enterprises already rely on feed into a continuously updated picture of enterprise posture. ServiceNow’s own security operations team runs Autonomous Risk & Security, handling incidents seven times faster than prior workflows using AI agents, with every action documented and every decision traceable.
Enterprises that establish this foundation of complete visibility, governed identities, integrated risk, and autonomous response will be decisively ahead as AI accelerates further. ServiceNow gives security and risk leaders a single view of how exposure, incidents, and identity decisions translate to enterprise risk posture in real time, with the audit trail regulators require.


