Using generative AI skills in ServiceNow Otto for Unified Security Exposure Management

  • Release version: Yokohama
  • Updated January 12, 2026
  • 3 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Using generative AI skills in ServiceNow Otto for Unified Security Exposure Management

    ServiceNow Otto for Unified Security Exposure Management leverages generative AI skills to empower vulnerability managers and analysts to resolve remediation tasks efficiently within their workflow. These AI capabilities provide contextual insights, automate approvals, and streamline vulnerability management processes directly in the ServiceNow platform.

    Show full answer Show less

    Key Features

    • Automatic Activation of AI Skills: New customers get designated generative AI skills and agentic workflows enabled by default upon installing Now Assist products. Existing customers upgrading to Yokohama Patch 11 have unconfigured skills auto-enabled, while previously disabled ones remain off.
    • Domain Separation and Data Privacy: AI skills operate within domain-separated environments, ensuring users access and generate insights only from their domain data. There is no data co-mingling, and AI service requests and responses are not persisted outside the instance.
    • Insight Generation and Prioritization: AI generates contextual summaries and actionable recommendations to help prioritize vulnerability findings, enhancing decision-making and security posture understanding.
    • Approval and False Positive Recommendations: The AI provides on-demand suggestions for exception approvals and false positive identifications, streamlining remediation workflows.
    • API Connector Assistance: Generative AI aids in automatically populating steps within the API Connector builder, accelerating integration setups (requires additional application activation).
    • Duplicate Vulnerable Item Identification: AI identifies and groups duplicate Vulnerable Items (VITs) from multiple scanners, highlighting primary items and assisting in closing duplicates to reduce noise.
    • Preferred Vulnerability Solutions Suggestion: The AI recommends the most appropriate vulnerability solutions for active host VITs. This requires installing the Vulnerability Solution Management application to import current solutions and integrates with third-party vendors.
    • Approval Impact Analysis Recommendations: AI generates recommendations to support approval impact analysis, helping improve remediation accuracy and effectiveness.

    Practical Considerations for ServiceNow Customers

    • Skills are available automatically to users with appropriate roles (e.g., ITIL roles) without modifying existing role assignments.
    • To fully leverage solution recommendations and API connector automation, customers must install and activate complementary applications such as Vulnerability Solution Management and relevant Now Assist products.
    • Vulnerable Items must meet specific criteria (e.g., active states like Open or Under Investigation, associated Configuration Item, and Vulnerability fields populated) to be eligible for AI-driven recommendations.
    • The solution supports improved vulnerability management workflows by reducing manual effort and improving prioritization accuracy through AI-powered insights.

    Expected Outcomes

    By using generative AI skills within ServiceNow Otto for Unified Security Exposure Management, customers can expect faster, more accurate vulnerability prioritization and remediation. The AI-driven insights and automation help reduce operational overhead, improve approval processes, and enhance overall security posture visibility, enabling teams to act decisively on critical security exposures.

    Vulnerability managers and analysts can resolve remediation tasks from within their flow of work with the generative AI skills supported by ServiceNow Otto for Unified Security Exposure Management.

    Some Now Assist skills, agents, and agentic workflows are turned on by default
    The skills are automatically available to appropriate role users for the application, such as ITIL roles on incident forms or change forms. This change simply activates the skill and does not touch the roles that may be needed to use the skill. The new default behavior works as follows:
    • New customers: When you install a Now Assist product, designated skills and agentic workflows are turned on automatically.
    • Existing customers who are upgrading (starting with Yokohama Patch 11): Any previously unconfigured skill, agent, or agentic workflow is turned on automatically (the AI asset was never configured and turned on, then turned off again). Previously configured skills and agentic workflows that were turned on, then off, remain inactive.

    Skills reuse

    By default, all skills exist in the global domain. When you use Now Assist in a domain-separated environment, users are only able to access data in their domain. For example, if a user uses the summarization skill, Now Assist only uses material that exists in the user's domain when generating that summary. Additionally, there is no co-mingling of data for domain-separated instances when using generative AI skills. The data resides only on the instance, and the shared services used for generative AI do not persist any requests (prompts) and responses. For more information, see Domain separation in the AI Admin Hub console. (Note that global domain is not the same as global scope. For more information, see Exploring Next Experience pickers.)

    Overview of ServiceNow Otto for Unified Security Exposure Management skills

    With generative AI skills with ServiceNow Otto for Unified Security Exposure Management, your vulnerability managers and analysts have the option to: