Using generative AI skills

  • Release version: Zurich
  • Updated July 29, 2026
  • 3 minutes to read
  • Summarize
    Summarized using AI
    This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.

    Summary of Using generative AI skills

    Generative AI skills in ServiceNow empower vulnerability managers and analysts to efficiently address remediation tasks by delivering automated insights, recommendations, and data analysis within their workflow. These AI capabilities are designed to enhance vulnerability management processes, providing contextual answers, solution suggestions, and approval recommendations.

    Show full answer Show less

    Access to generative AI features depends on your ServiceNow license. AI skills operate within domain-separated environments, ensuring data privacy by limiting AI-generated content to domain-specific data without sharing or persisting requests externally.

    Key Features

    • Security Exposure 360: Allows users to ask plain-language questions to obtain comprehensive answers about vulnerabilities across hosts, containers, and test results.
    • AI Guardrails Helper Skill and Agentic Workflow: Helps identify types of findings, understand guardrail mappings, and determine mitigated or deferred findings (USEM workspace only).
    • Vulnerability Insights Generation: Provides contextual summaries and actionable recommendations to better understand security posture and prioritize critical issues.
    • Exception and False Positive Approval Recommendations: Offers on-demand suggestions to streamline approval decisions for exceptions and false positives.
    • API Connector Creation: Assists developers and admins by auto-populating steps in the API Connector builder (requires activation of specific applications).
    • Duplicate Vulnerable Item Identification: Detects and groups duplicate vulnerability items from multiple scanners, enabling cleanup and consolidation.
    • Vulnerability Solution Suggestions: Recommends the most appropriate solutions for active host vulnerabilities, leveraging the Vulnerability Solution Management application and third-party vendor data.
    • Approval Impact Analysis Recommendations: Facilitates approval workflows by generating AI-driven impact analyses for exception and false positive requests.

    Practical Benefits for ServiceNow Customers

    By integrating generative AI skills, your security teams can expect:

    • Accelerated vulnerability assessment and remediation through AI-driven insights and recommendations.
    • Improved accuracy and efficiency in managing exceptions, false positives, and duplicate findings.
    • Enhanced security posture visibility with AI-generated summaries tailored to your domain.
    • Streamlined API connector development to integrate with external systems more easily.
    • Compliance with domain separation policies ensuring data security and privacy within your instance.

    These capabilities help your teams act faster and more confidently on security findings, improving overall vulnerability management outcomes.

    AI skills help vulnerability managers and analysts resolve remediation tasks within their flow of work by providing automated insights, recommendations, and data analysis.

    Note:
    Depending on your license, you will have access to certain application features, generative AI skills, agentic workflows, and AI agents. For more information, see .

    Skills in global domain reuse

    By default, all skills exist in the global domain. When you use AI in a domain-separated environment, users are only able to access data in their domain. For example, if a user uses the summarization skill, AI only uses material that exists in the user's domain when generating that summary. Additionally, there is no co-mingling of data for domain-separated instances when using generative AI skills. The data resides only on the instance, and the shared services used for generative AI do not persist any requests (prompts) and responses. For more information, see Domain separation in the Now Assist Admin console. (Note that global domain is not the same as global scope. For more information, see Exploring Next Experience pickers.)

    Overview of available ServiceNow Otto for Unified Security Exposure Management skills

    With generative AI skills with ServiceNow Otto for Unified Security Exposure Management, your vulnerability managers and analysts have the option to use generative AI skills to help them with the following tasks. Unless otherwise noted, these generative AI skills are supported in both the legacy and Unified Security Exposure Management (USEM) workspaces.

    Generative AI skill Description Users
    Evaluate vulnerability exposure data with Security Exposure 360 Enter questions in plain language to receive comprehensive answers about findings for host, container, and test results vulnerabilities. Vulnerability managers and analysts
    Using the AI guardrails helper skill and agentic workflow
    Identify finding types, understand mapped guardrails, and see why specific findings were selected for mapping. This information helps you determine which findings are already mitigated or deferred for later review.
    Note:
    Supported only in the Unified Security Exposure Management (USEM) workspace.
    Vulnerability analysts, vulnerability managers, and chief information security officers (CISOs)
    Generate vulnerability insights with generative AI Receive insights based on contextual summaries and see actionable recommendations. Vulnerability managers and analysts
    Get exception and false positive approval recommendations Receive on-demand approval and false positive recommendations. Exception and false positive approvers
    Create an API connector with generative AI

    Automatically populate steps in the API Connector builder.

    Note:
    You must install and activate the required applications and ServiceNow Otto for Unified Security Exposure Management to use the generative AI skill to help you create your own API connector.
    Developers in your organization, vulnerability and security admins
    Identify duplicate vulnerable items with generative AI Identify and group duplicate vulnerable items (VITs) created from multiple scanners. Identify the primary vulnerable item and remove (close) duplicates. Vulnerability managers and analysts
    Suggest vulnerability solutions with generative AI

    Identify the most appropriate preferred solution for a given vulnerable item (VIT).

    Requirements:

    • You must install and activate Vulnerability Solution Management [sn_vul_solution] to import and view preferred and available vulnerability solutions. This application provides you with current solutions with scheduled imports. Vulnerability Solution Management is available on the ServiceNow® Store.
    • This generative AI skill supports only active host vulnerable items (VITs). VITs must be in the Open, Under Investigation, Awaiting Implementation, or In Review states.
    • Current solutions that most effectively address vulnerabilities, also referred to as solutions of the highest supersedence, must be available for you to import from third-party vendors. See Vulnerability Solution Management for more information about Vulnerability Solution Management and supported integrations for more information.
    • The Configuration item field on a VIT must be populated with a value from the Configuration Item [cmdb_ci] table.
    • The Vulnerability field on a VIT must be populated.
    Vulnerability managers and analysts
    Generate vulnerability insights with generative AI Understand your security posture with AI-generated summaries and recommendations to help you prioritize and act on critical findings. Vulnerability managers and analysts
    Generate a recommendation for approval impact analysis Streamline the approval process for exceptions and false positive requests with AI-driven recommendations. Vulnerability managers and analysts