---
sourceDocument: Australia Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/platform-security

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Agentic AI security and governance

# Agentic AI security and governance {#ariaid-title1}

* Release version: Australia
* 
* Updated April 23, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Agentic AI security and governance

Agentic AI security and governance in Now Assist ensures AI agents operate securely within defined boundaries through layered controls.
These controls regulate who can invoke agents, their data access, interaction monitoring, and organizational oversight.
Since AI agents act autonomously---invoking tools, accessing data, and making decisions---security must be enforced at multiple layers including permissions, data protection, activity logging, and runtime behavior monitoring.
Show full answer Show less  
Built on the ServiceNow AI Platform security model, these controls extend existing ACLs, role-based access, and domain separation to address agentic AI specifics like identity classification, role masking, and AI Guardian runtime guardrails. Readiness assessment tools help verify your instance's preparedness before deployment.

## Key Features

* **Permissions-based Access Control:** Use Agent Role Inheritance, identity types, and granular roles to ensure AI agents have only the permissions necessary, limiting their actions to intended scopes.
* **Data Protection:** Employ ServiceNow security tools such as Key Management Framework, Field Encryption, and Data Classification to safeguard data storage, processing, and isolation---especially when third-party agents are involved.
* **Agent Traceability and Monitoring:** Utilize AI Control Tower and agent activity logs to track agent actions, data accessed, and maintain auditable, explainable records for security and compliance.
* **Governance and Administrative Safeguards:** Manage roles, policies, and configurations to reduce risk and support compliance standards including HIPAA, GDPR, and NIST.
* **AI Threat Protection:** Now Assist leverages AI Guardian, built on the ServiceNow Small Language Model (SLM), to detect and defend against AI-specific threats such as offensive content, prompt injection attacks, and sensitive topic detection.
* **External AI Agent Security:** Provides visibility and governance over AI agents from external providers, ensuring sensitive data remains isolated and third-party data flows are monitored.

## Key Outcomes

By implementing these security and governance controls, ServiceNow customers can confidently deploy AI agents that function autonomously while maintaining strict security, compliance, and oversight. Customers gain enhanced protection against AI-specific risks, maintain control over agent permissions and data access, and ensure traceability and auditability of AI activities. This comprehensive approach supports safe AI adoption aligned with organizational policies and regulatory requirements.

Additionally, tools like AI Guardian and AI Control Tower empower organizations to monitor generative AI interactions in real time, providing runtime safeguards and operational visibility throughout the AI lifecycle.  
Now Assist AI agents operate securely within the boundaries you define. Layered controls govern who can invoke each agent, what data it can access, how interactions are monitored, and how your organization retains
oversight.
Deploying AI agents introduces security considerations that go beyond standard platform hardening. Agents act autonomously, invoke tools, access data, and make decisions on behalf of users. This requires controls at every layer: who
can invoke an agent, what it can access once running, how its actions are logged, and what catches harmful or unintended behavior at runtime.

Now Assist is built on the ServiceNow AI Platform security model. AI agents are subject to the same ACL enforcement, role-based access controls, and domain separation that govern all platform activity. The controls in these sections extend that foundation with
capabilities specific to agentic AI. These include identity classification for AI users, role masking to enforce least-privilege during tool execution, and runtime guardrails through AI Guardian. Readiness assessment tools help verify your instance is prepared before agents go to production.

## AI security concepts {#now-assist-security__section_a3f_bx4_w3c}

|-|-|-|
| [Permissions-based access controlUse Agent Role Inheritance, identity types, and granular roles to verify your AI agents have only the permissions they need, and can act only within their intended boundaries.](https://www.servicenow.com/docs/PqgJz4VedglA3qfEy1FqgQ "Use Agent Role Inheritance, identity types, and granular roles to verify your AI agents have only the permissions they need, and can act only within their intended boundaries.") | [Data protectionLearn how ServiceNow tools like Key Management Framework, Field Encryption, and Data Classification protect your data, including where it is stored and processed, and how it stays isolated when third-party agents are involved.](https://www.servicenow.com/docs/vtaj~oE2VNWkDW~9M~I_Eg "Learn how ServiceNow security tools such as the Key Management Framework, Field Encryption, and Data Classification work to keep your data secure.") | [Agent traceability and monitoringUse AI Control Tower and agent activity logs to track what your agents do, what data they access, and when, and provide the auditable, explainable records your security and compliance teams require.](https://www.servicenow.com/docs/CX5WXfXvGUzvkTAdipXglw "Learn how to use tools like AI Control Tower to track, monitor, and report on your AI assets.") |
| [Governance and admin safeguardsFind guidance on managing roles, policies, and configurations to reduce risk and meet compliance requirements, including HIPAA, GDPR, and NIST.](https://www.servicenow.com/docs/HvjS9~enPslP9kKvHo9vFQ "Find guidance on preparing your instance for AI deployment, maintaining domain separation, and reducing risk across your Now Assist implementation.") | [AI threat protectionLearn how Now Assist helps defend against AI-specific threats including offensive content, prompt injection, and sensitive subject detection using AI Guardian.](https://www.servicenow.com/docs/XsLEAWj8y5NdAPDRlQpTPQ "Learn how Now Assist helps defend against AI-specific threats including offensive content, prompt injection, and sensitive subject detection using AI Guardian.") | [External AI agent securityLearn how to monitor and govern AI agents from external providers, with visibility into third-party data flows and assurances that sensitive data stays properly isolated across your AI ecosystem.](https://www.servicenow.com/docs/RNKqVEvdpW~hRTSVHv7k_g "Learn how to monitor and govern AI agents from external providers, with visibility into third-party data flows and assurances that sensitive data stays properly isolated across your AI ecosystem.") |
[ ]

{#now-assist-security__table_udv_5wf_d3c}

## AI security products {#now-assist-security__section_vch_bbp_w3c}

|-|-|-|
| [Now Assist GuardianAI Guardian is built on the ServiceNow Small Language Model (SLM) and monitors generative AI interactions to detect offensive content, prompt injection attacks, and sensitive topics.](https://www.servicenow.com/docs/QYIxXynVKkrQ1N2mQp1G~w "AI Guardian is built on the ServiceNow Small Language Model (SLM) and monitors generative AI interactions to detect offensive content, prompt injection attacks, and sensitive topics.") |   | [AI Control TowerThe AI Control Tower is a platform that connects different parts of an organization to speed up the AI adoption.](https://www.servicenow.com/docs/access?context=ai-control-tower-landing&version=australia&pubname=australia-intelligent-experiences&ft:locale=en-US) |
[ ]

{#now-assist-security__table_bm1_dbp_w3c}
* **[Permissions-based access control](https://www.servicenow.com/docs/PqgJz4VedglA3qfEy1FqgQ)**   
  Use Agent Role Inheritance, identity types, and granular roles to verify your AI agents have only the permissions they need, and can act only within their intended boundaries.
* **[Data protection](https://www.servicenow.com/docs/vtaj~oE2VNWkDW~9M~I_Eg)**   
  Learn how ServiceNow security tools such as the Key Management Framework, Field Encryption, and Data Classification work to keep your data secure.
* **[Agent traceability and monitoring](https://www.servicenow.com/docs/CX5WXfXvGUzvkTAdipXglw)**   
  Learn how to use tools like AI Control Tower to track, monitor, and report on your AI assets.
* **[Governance and admin safeguards](https://www.servicenow.com/docs/HvjS9~enPslP9kKvHo9vFQ)**   
  Find guidance on preparing your instance for AI deployment, maintaining domain separation, and reducing risk across your Now Assist implementation.
* **[AI threat protection](https://www.servicenow.com/docs/XsLEAWj8y5NdAPDRlQpTPQ)**   
  Learn how Now Assist helps defend against AI-specific threats including offensive content, prompt injection, and sensitive subject detection using AI Guardian.
* **[External AI agent security](https://www.servicenow.com/docs/RNKqVEvdpW~hRTSVHv7k_g)**   
  Learn how to monitor and govern AI agents from external providers, with visibility into third-party data flows and assurances that sensitive data stays properly isolated across your AI ecosystem.
* **[AI Guardian](https://www.servicenow.com/docs/QYIxXynVKkrQ1N2mQp1G~w)**   
  AI Guardian is built on the ServiceNow Small Language Model (SLM) and monitors generative AI interactions to detect offensive content, prompt injection attacks, and sensitive topics.
* **[Create and secure an AI agent in Now Assist](https://www.servicenow.com/docs/bm3hK0ig3n5~WSsV~NRwUQ)**   
  Plan, build, secure, test, and deploy a Now Assist AI agent.

