---
sourceDocument: Australia Security Management
sourceDocumentLink: https://www.servicenow.com/docs/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# AI Security Exposure Management

# Exploring AI Security Exposure Management {#ariaid-title1}

Release version: Australia  
Updated September 3, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Exploring AI Security Exposure Management

AI Security Exposure Management, part of the Unified Security Exposure Management suite, helps organizations manage AI-related security risks by integrating with third-party AI security products.
It addresses emerging AI attack surfaces such as vulnerabilities in open source AI models, harmful AI behaviors, and AI infrastructure configuration issues.
This capability enables vulnerability teams to identify, prioritize, and remediate AI security exposures efficiently, reducing the meantime to remediate high-risk issues.
Show full answer Show less  

## Key Features

* **AI Exposure Identification:** Detects AI vulnerabilities, validation findings (behavioral risks), and posture findings (configuration issues) through integrations with external AI security tools and static scans of AI models.
* **Guardrails Detection:** Uses an AI skill to identify existing runtime protection policies (guardrails) that mitigate risky AI behaviors, supporting automated deferral of findings with mitigations.
* **Agentic Workflow Automation:** Automates deferral of mitigated findings and enables creation of exception rules to streamline vulnerability management workflows.
* **AI Asset Remediation via Employee Center:** Integrates with Employee Center and third-party tools to assign remediation tasks directly to AI asset owners, accelerating response and simplifying remediation by involving asset owners directly.
* **Third-Party Integrations and Data Import:** Supports imports of AI inventory data and security findings into the ServiceNow AI Platform® CMDB, linking findings to AI assets for comprehensive management.
* **MITRE ATLAS Alignment:** Associates all AI security findings with MITRE ATLAS tactics and techniques for contextual threat understanding.

## Users and Roles

Primarily designed for vulnerability analysts, managers, and Chief Information Security Officers (CISOs), the module helps these roles monitor AI risk posture, assign remediation tasks based on asset ownership and severity, and generate actionable dashboards and reports for stakeholders. It supports teams dealing with high volumes of AI exposures, such as those migrating legacy systems to AI-native applications.

## Benefits

* **Comprehensive AI Attack Surface Visibility:** Provides unified insight into AI vulnerabilities, behavioral risks, and configuration issues.
* **Optimized Remediation Workflows:** Prioritizes high-risk exposures and defers low-risk findings mitigated by guardrails, improving efficiency.
* **Faster Response Times:** Direct remediation tasks assigned to AI asset owners reduce complexity and accelerate issue resolution.

## Next Steps for Customers

* Configure and use AI Security Exposure Management to view AI exposures and set up integrations.
* Leverage the AI guardrails helper skill and agentic workflows to understand findings and automate deferrals.
* Implement AI remediation workflows via Employee Center to engage asset owners in resolving AI posture findings.  
AI Security Exposure Management is a part of the Unified Security Exposure Management product suite of applications. AI Security Exposure Management integrates with third-party AI security products to help you manage various types of potential AI exposure across your
environment.

## AI Security Exposure Management overview {#exploring-ai-security-exposure__cf-exploring-parent-overview}

With the rapid growth and adoption of AI in enterprises, a new attack surface is emerging in the form of AI security exposures. This attack surface includes open source AI model vulnerabilities and AI model behavioral risks with
harmful prompts that could result in security breaches and data loss during runtime. In addition, AI infrastructure configuration issues might exist in AI agents, data sets, or any other type of AI assets in your environment.

AI Security Exposure Management can help your organization efficiently manage AI security exposures such as AI model vulnerabilities, harmful AI model behavior, and AI infrastructure configuration issues.

Use the [Guardrails Detector skill](https://www.servicenow.com/docs/FQmdvLEryKFp8nI8GejSPA "You have the option to use a generative AI skill and agentic workflow to help you understand what type of findings you have, understand the guardrails associated with findings, and see why the skill mapped guardrails to particular findings.") to identify existing guardrails that can mitigate some of the AI validation findings that indicate risky behavior of the AI application or model.

Use an [agentic workflow](https://www.servicenow.com/docs/iQh3Vd3kjtg5IXKa1bucAw "Use the AI agent to ask about guardrails identified by the AI skill component in the AI Guardrails Helper. Automatically defer findings with existing mitigations in the form of guardrails and create exception rules to automatically defer future findings.") to automate the deferral of findings that have mitigations or guardrails and create exception rules to auto-defer future findings.

With AI Security Exposure Management, vulnerability managers can prioritize high risk exposures and defer low risk exposures that might have mitigations or guardrails already in place. This prioritization ultimately helps
vulnerability management teams optimize remediation workflows to help them reduce the meantime to remediate their high risk exposures.

## AI asset remediation in Employee Center {#exploring-ai-security-exposure__section_tbk_r1b_3kc}

AI Security Exposure Management integrates with Employee Center and third-party security tools to enable AI asset owners to remediate AI vulnerabilities directly through AI exposure tasks. These tasks can reduce response by appealing directly to the asset owner and
avoid the time and technical complexity of traditional vulnerability analysts. See [Using AI remediation workflows with Employee Center](https://www.servicenow.com/docs/TL6nci2X596azkEd1AKX1Q "AI Security Exposure Management integrates with Employee Center and third-party security tools to enable AI asset owners to remediate AI posture findings (configuration issues) directly through lightweight tasks.") for more information.

## Key terms for AI Security Exposure Management {#exploring-ai-security-exposure__section_wql_2zv_w3c}

Navigate to WorkspacesSecurity Exposure ManagementAI Exposures.  

AI vulnerabilities
:   Vulnerabilities that are discovered in open source AI models that are published in repositories. Third-party integrations perform static scans of AI models for these vulnerabilities. The findings (AISF) generated by this
    application are generally open source, but other models such as self-hosted models are also supported. A finding is created when a known model vulnerability or behavior can be matched to an AI model (asset) in your CMDB.  
    The following types of findings are generated and maintained AI Security Exposure Management (AISEC):

    * AI Vulnerability Finding (AIVUL)
    * AI Validation Finding (AIVF)
    * AI Posture Finding (AIPF)
    {#exploring-ai-security-exposure__ul_vct_qg4_djc}

AI validation findings
:   Findings from third-party automated penetration testing or automated red teaming done to verify the behavior of AI applications or models by validating them against their prompt libraries. For example, third-party vendors test AI
    applications for issues like Personally Identifiable Information (PII) leakage.

AI posture findings
:   Configuration issues in AI agents, tools, prompts, MCP servers that are detected by third-party AI security tools in various platforms such as Microsoft Copilot Studio, AWS, and others.

Service Graph Connector
:   Type of third-party integration that imports AI inventory data into your CMDB.

AI security exposure management integrations
:   Third-party integrations that import AI vulnerabilities, validation findings, and posture or configuration findings from AI security tools into tables in your ServiceNow AI Platform® instance.

Guardrails detection

:   AI security platforms support runtime protection policies or guardrails that can detect AI behavior risks such as sensitive information disclosure and block or redact the content in the payload.

    ServiceNow® AI Security Exposure Management employs an AI skill to map these guardrails that are enabled in AI security platforms with the AI validation findings (automated red teaming results) that are reported
    by those platforms. This information about available guardrails can be used by vulnerability analysts to defer AI validation findings that are mitigated by these guardrails.

MITRE ATLAS techniques

:   AI security platforms associate all the findings, that is, vulnerabilities, validation findings, and posture findings, with relevant MITRE ATLAS tactics and techniques. This information is imported by your ServiceNow AI Platform® instance and displayed as part of the AI security finding details.

## AI Security Exposure Management users {#exploring-ai-security-exposure__cf-exploring-parent-users}

As an example, consider a vulnerability analyst and a vulnerability team that is working for a large financial services company. The team is in the process of converting legacy applications into AI-native applications and is
encountering a high volume of AI exposures. To help them mitigate high risk exposure threats and identify and defer AI security issues that have guardrails already in place for their large volume of exposures, this vulnerability team
requires an automated remediation workflow.
{#exploring-ai-security-exposure__table_omj_wry_q3c__entry__2}

| User | Description |
|-|-|
| Vulnerability analysts, vulnerability managers, and Chief Information Security Officers (CISO) | Monitor the organization's overall risk posture across integrated environments, ensuring accurate asset discovery and classification for AI exposures correlation. These roles serve as an escalation point for remediation teams. They assign remediation tasks based on asset ownership and severity, and organize AI exposure information into dynamic remediation tasks to streamline prioritization. Additionally, these roles deliver actionable dashboards and reports to track remediation progress, highlight critical AI exposures, and communicate the current risk posture to stakeholders. |
[Table 1. Users]

{#exploring-ai-security-exposure__table_omj_wry_q3c}

## AI Security Exposure Management benefits {#exploring-ai-security-exposure__cf-exploring-parent-benefits}

{#exploring-ai-security-exposure__table_rmj_wry_q3c__entry__3}

| Benefit | Feature | Users |
|-|-|-|
| A dedicated module, AI Security Exposure Management, that provides visibility into the entire AI attack surface, including vulnerabilities, validation or automated red teaming findings, and security posture findings or configuration issues in various AI assets. | AI Security Exposure Management module | Vulnerability analysts, vulnerability management teams, Chief Information Security Officers (CISO). |
| AI exposure tasks mapped directly to AI asset owners in Employee Centers can reduce response time by appealing directly to the asset owner and avoid the time and technical complexity of traditional vulnerability analysts. | Employee center AI asset remediation workflow | Employees, developers, vulnerability managers and analysts |
[ ]

{#exploring-ai-security-exposure__table_rmj_wry_q3c}

## What to explore next {#exploring-ai-security-exposure__cf-exploring-parent-links}

To learn more about configuring and using AI Security Exposure Management, see:

* [Viewing AI Exposures](https://www.servicenow.com/docs/P8GUyl9Gm5LN36RikAsmpg "Access the entire attack surface across various types of findings on the AI Security Exposure Management dashboard with the AI Exposures module. AI Security Exposure Management is a dedicated module of the Security Exposure Management workspace.")
* [Install and configure AI Security Exposure Management](https://www.servicenow.com/docs/GTk7cYyzziaPpnYQxHiJAg "Install and configure the required applications.")
* [Using the AI guardrails helper skill and agentic workflow](https://www.servicenow.com/docs/FQmdvLEryKFp8nI8GejSPA "You have the option to use a generative AI skill and agentic workflow to help you understand what type of findings you have, understand the guardrails associated with findings, and see why the skill mapped guardrails to particular findings.")
* [Configuring remediation task rules](https://www.servicenow.com/docs/RmdlpBHNSZWENp1hmEfORQ#sem-configure-remediation-task-rules "By configuring remediation task rules, you can automatically group findings based on filter conditions.")
{#exploring-ai-security-exposure__ul_smj_wry_q3c}
* **[Using the AI guardrails helper skill and agentic workflow](https://www.servicenow.com/docs/FQmdvLEryKFp8nI8GejSPA)**   
  You have the option to use a generative AI skill and agentic workflow to help you understand what type of findings you have, understand the guardrails associated with findings, and see why the skill mapped guardrails to particular findings.
* **[Using AI remediation workflows with Employee Center](https://www.servicenow.com/docs/TL6nci2X596azkEd1AKX1Q)**   
  AI Security Exposure Management integrates with Employee Center and third-party security tools to enable AI asset owners to remediate AI posture findings (configuration issues) directly through lightweight tasks.

*[\>]: and then


