---
sourceDocument: Brazil Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/security-management

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# AI Security Exposure Management

# Exploring AI Security Exposure Management {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Exploring AI Security Exposure Management

AI Security Exposure Management is part of the Unified Security Exposure Management suite and integrates with third-party AI security products to help ServiceNow customers identify and manage AI-related security risks in their environments.
This solution addresses new AI attack surfaces emerging from vulnerabilities in open-source AI models, harmful AI behaviors, and misconfigurations in AI infrastructure, such as agents and data sets.
Show full answer Show less  
By leveraging guardrails detection and agentic workflows, vulnerability teams can automate the deferral of findings that have existing mitigations, prioritize high-risk AI exposures, and streamline remediation efforts, ultimately reducing the meantime to remediate critical issues.

## Key Features

* **Integration with Third-Party AI Security Tools:** Imports AI vulnerabilities, validation findings, and posture/configuration issues into ServiceNow's AI Platform, enhancing visibility and correlation of AI security exposures.
* **Guardrails Detection Skill:** Identifies AI runtime protection policies that mitigate risky AI behaviors, enabling automated deferral of mitigated findings and creation of exception rules.
* **Agentic Workflow Automation:** Helps automate deferral and remediation workflows, facilitating prioritization and efficient management of AI security exposures.
* **AI Asset Remediation via Employee Center:** Enables direct assignment of AI exposure remediation tasks to AI asset owners, reducing response times and minimizing reliance on vulnerability analysts for technical complexity.
* **MITRE ATLAS Technique Mapping:** Associates AI findings with MITRE ATLAS tactics and techniques, providing context and aiding prioritization.

## Key Outcomes

* **Comprehensive AI Attack Surface Visibility:** Customers gain insight into vulnerabilities, behavioral risks, and configuration issues across their AI assets.
* **Optimized Vulnerability Management:** Teams can prioritize high-risk AI exposures, defer low-risk issues with existing guardrails, and automate workflows to reduce remediation times.
* **Improved Collaboration and Response:** Direct remediation tasks sent to AI asset owners via Employee Center accelerate issue resolution and decrease workload on vulnerability analysts.
* **Enhanced Risk Posture Monitoring:** Dashboards and reports help vulnerability analysts, managers, and CISOs monitor and communicate the organization's AI risk posture effectively.

## Practical Considerations for ServiceNow Customers

ServiceNow customers implementing AI Security Exposure Management should focus on integrating their third-party AI security tools to import relevant findings, configuring guardrails detection and agentic workflows to automate deferral and remediation tasks, and leveraging Employee Center for direct AI asset owner engagement. This enables efficient management of AI security risks and accelerates remediation efforts in AI-native and legacy application environments.  
AI Security Exposure Management is a part of the Unified Security Exposure Management product suite of applications. AI Security Exposure Management integrates with third-party AI security products to help you manage various types of potential AI exposure across your
environment.

## AI Security Exposure Management overview {#exploring-ai-security-exposure__cf-exploring-parent-overview}

With the rapid growth and adoption of AI in enterprises, a new attack surface is emerging in the form of AI security exposures. This attack surface includes open source AI model vulnerabilities and AI model behavioral risks with
harmful prompts that could result in security breaches and data loss during runtime. In addition, AI infrastructure configuration issues might exist in AI agents, data sets, or any other type of AI assets in your environment.

AI Security Exposure Management can help your organization efficiently manage AI security exposures such as AI model vulnerabilities, harmful AI model behavior, and AI infrastructure configuration issues.

Use the [Guardrails Detector skill](https://www.servicenow.com/docs/GdcoICWlWGiz0ASckt~C1Q "The AI guardrails helper skill and agentic workflow can help you understand finding types, associated guardrails, and how guardrails map to findings. See what type of findings you have, understand the guardrails associated with findings, and see why the skill to mapped guardrails to particular findings.") to identify existing guardrails that can mitigate some of the AI validation findings that indicate risky behavior of the AI application or model.

Use an [agentic workflow](https://www.servicenow.com/docs/I5osdrkBtFOTOyvlzx~INw "Use the AI agent to ask about the guardrails that were identified by the AI skill component in the AI Guardrails Helper, automatically defer findings with existing mitigations in the form of guardrails, or create exception rules to auto-defer future findings.") to automate the deferral of findings that have mitigations or guardrails and create exception rules to auto-defer future findings.

With AI Security Exposure Management, vulnerability managers can prioritize high risk exposures and defer low risk exposures that might have mitigations or guardrails already in place. This prioritization ultimately helps
vulnerability management teams optimize remediation workflows to help them reduce the meantime to remediate their high risk exposures.

## AI asset remediation in Employee Center {#exploring-ai-security-exposure__section_tbk_r1b_3kc}

AI Security Exposure Management integrates with Employee Center and third-party security tools to enable AI asset owners to remediate AI vulnerabilities directly through AI exposure tasks. These tasks can reduce response by appealing directly to the asset owner and
avoid the time and technical complexity of traditional vulnerability analysts. See [Using AI remediation workflows with Employee Center](https://www.servicenow.com/docs/IENPAXhpYNSwz7RAjNnWZg "AI Security Exposure Management integrates with Employee Center and third-party security tools to enable AI asset owners to remediate AI posture findings (configuration issues) directly through lightweight tasks. These tasks can reduce time to remediate (TTR) by assigning a task directly to the asset owner.") for more information.

## Key terms for AI Security Exposure Management {#exploring-ai-security-exposure__section_wql_2zv_w3c}

Navigate to WorkspacesSecurity Exposure ManagementAI Exposures.  

AI vulnerabilities
:   Vulnerabilities that are discovered in open source AI models that are published in repositories. Third-party integrations perform static scans of AI models for these vulnerabilities. The findings (AISF) generated by this
    application are generally open source, but other models such as self-hosted models are also supported. A finding is created when a known model vulnerability or behavior can be matched to an AI model (asset) in your CMDB.  
    The following types of findings are generated and maintained AI Security Exposure Management (AISEC):

    * AI Vulnerability Finding (AIVUL)
    * AI Validation Finding (AIVF)
    * AI Posture Finding (AIPF)
    {#exploring-ai-security-exposure__ul_vct_qg4_djc}

AI validation findings
:   Findings from third-party automated penetration testing or automated red teaming done to verify the behavior of AI applications or models by validating them against their prompt libraries. For example, third-party vendors test AI
    applications for issues like Personally Identifiable Information (PII) leakage.

AI posture findings
:   Configuration issues in AI agents, tools, prompts, MCP servers that are detected by third-party AI security tools in various platforms such as Microsoft Copilot Studio, AWS, and others.

Service Graph Connector
:   Type of third-party integration that imports AI inventory data into your CMDB.

AI security exposure management integrations
:   Third-party integrations that import AI vulnerabilities, validation findings, and posture or configuration findings from AI security tools into tables in your ServiceNow AI Platform® instance.

Guardrails detection

:   AI security platforms support runtime protection policies or guardrails that can detect AI behavior risks such as sensitive information disclosure and block or redact the content in the payload.

    ServiceNow® AI Security Exposure Management employs an AI skill to map these guardrails that are enabled in AI security platforms with the AI validation findings (automated red teaming results) that are reported
    by those platforms. This information about available guardrails can be used by vulnerability analysts to defer AI validation findings that are mitigated by these guardrails.

MITRE ATLAS techniques

:   AI security platforms associate all the findings, that is, vulnerabilities, validation findings, and posture findings, with relevant MITRE ATLAS tactics and techniques. This information is imported by your ServiceNow AI Platform® instance and displayed as part of the AI security finding details.

## AI Security Exposure Management users {#exploring-ai-security-exposure__cf-exploring-parent-users}

As an example, consider a vulnerability analyst and a vulnerability team that is working for a large financial services company. The team is in the process of converting legacy applications into AI-native applications and is
encountering a high volume of AI exposures. To help them mitigate high risk exposure threats and identify and defer AI security issues that have guardrails already in place for their large volume of exposures, this vulnerability team
requires an automated remediation workflow.
{#exploring-ai-security-exposure__table_omj_wry_q3c__entry__2}

| User | Description |
|-|-|
| Vulnerability analysts, vulnerability managers, and Chief Information Security Officers (CISO) | Monitor the organization's overall risk posture across integrated environments, ensuring accurate asset discovery and classification for AI exposures correlation. These roles serve as an escalation point for remediation teams. They assign remediation tasks based on asset ownership and severity, and organize AI exposure information into dynamic remediation tasks to streamline prioritization. Additionally, these roles deliver actionable dashboards and reports to track remediation progress, highlight critical AI exposures, and communicate the current risk posture to stakeholders. |
[Table 1. Users]

{#exploring-ai-security-exposure__table_omj_wry_q3c}

## AI Security Exposure Management benefits {#exploring-ai-security-exposure__cf-exploring-parent-benefits}

{#exploring-ai-security-exposure__table_rmj_wry_q3c__entry__3}

| Benefit | Feature | Users |
|-|-|-|
| A dedicated module, AI Security Exposure Management, that provides visibility into the entire AI attack surface, including vulnerabilities, validation or automated red teaming findings, and security posture findings or configuration issues in various AI assets. | AI Security Exposure Management module | Vulnerability analysts, vulnerability management teams, Chief Information Security Officers (CISO). |
| AI exposure tasks mapped directly to AI asset owners in Employee Centers can reduce response time by appealing directly to the asset owner and avoid the time and technical complexity of traditional vulnerability analysts. | Employee center AI asset remediation workflow | Employees, developers, vulnerability managers and analysts |
[ ]

{#exploring-ai-security-exposure__table_rmj_wry_q3c}

## What to explore next {#exploring-ai-security-exposure__cf-exploring-parent-links}

To learn more about configuring and using AI Security Exposure Management, see:

* [Viewing AI Exposures](https://www.servicenow.com/docs/Ix0wBK54j63IfssnnZA55Q "Access the entire attack surface across various types of findings on the AI Security Exposure Management dashboard with the AI Exposures module. AI Security Exposure Management is a dedicated module of the Security Exposure Management workspace.")
* [Install and configure AI Security Exposure Management](https://www.servicenow.com/docs/0PvSkVtuNfC9Da0nj6I0lg "Install and configure the required applications.")
* [Using the AI guardrails helper skill and agentic workflow](https://www.servicenow.com/docs/GdcoICWlWGiz0ASckt~C1Q "The AI guardrails helper skill and agentic workflow can help you understand finding types, associated guardrails, and how guardrails map to findings. See what type of findings you have, understand the guardrails associated with findings, and see why the skill to mapped guardrails to particular findings.")
* [Configuring remediation task rules](https://www.servicenow.com/docs/TUwS74XRRy2nRAmvqWBpGA#sem-configure-remediation-task-rules "By configuring remediation task rules, you can automatically group findings based on filter conditions.")
{#exploring-ai-security-exposure__ul_smj_wry_q3c}

*[\>]: and then


