How ServiceNow is pioneering autonomous security

Security employees discussing work

As the security community gathers at Black Hat USA 2026 in Las Vegas to confront increasingly sophisticated threat vectors, ServiceNow is making one thing unmistakable: We’re moving beyond legacy security models that struggle to keep pace with agentic businesses.

Following major architectural expansions, including the integration of Armis and Veza into the ServiceNow AI Platform to unify our security offering, we’ve established ServiceNow as the operational backbone for autonomous security.

At the foundation of this is our platform's ability to sense, decide, act, and secure across the entire enterprise—including identities, assets, vulnerabilities, and workflows—using a single, continuously updated plane and security graph.

This synthetic world model enables agentic security to operate with complete contextual awareness. It can understand an enterprise's ever-changing attack surface, which threats pose the greatest risk, and optimal remediation paths—all at machine speed.

The AI Centre for Cyber Defence

To spearhead this operational revolution, I’m incredibly proud to lead the ServiceNow AI Centre for Cyber Defence. This global hub is core to our security innovation engine with a mandate to pioneer the industry’s transition from reactive security to autonomous security.

The threat landscape has fundamentally changed. Attackers are weaponising generative AI, compressing the timeline between vulnerability discovery and exploitation from months to minutes, according to Government Technology. Human-configured rules and static automation often can’t move fast enough to protect complex enterprise operations.

We’ve created the AI Centre for Cyber Defence to completely flip the script. The centre is entirely dedicated to mastering cutting-edge AI models and developing the agentic expertise needed to outpace and outsmart these new attack methods before they can disrupt business.

An elite cyber brain trust

Building a paradigm-shifting centre like this requires more than just advanced algorithms; it needs the sharpest minds. ServiceNow has systematically assembled a world-class cybersecurity "dream team."

By bringing together ServiceNow's proven security and risk leaders, made up of architects and practitioners who’ve built our platform's security foundation, with the elite founders, innovators, and engineering leadership from Armis and Veza, as well as CTCI, Silk Security, and OTORIO (previously acquired by Armis), we've created a unified powerhouse.

This combined brain trust has a track record of building disruptive technologies, identifying emerging threats, and scaling world-class platforms. With this collective of security practitioners, demonstrated innovators, validated entrepreneurs, and visionary technologists unified under the AI centre mandate, we're positioned to scale this integrated model across the entire enterprise security landscape.

We’re focusing our collective engineering muscle and extensive cyber knowledge to achieve Shift Zero, which helps eliminate vulnerability backlogs entirely.

Mission and scope

The centre bridges the divide between deep AI engineering and practical, platform-wide cyber execution. We’re focusing our collective engineering muscle and extensive cyber knowledge to achieve Shift Zero, which helps eliminate vulnerability backlogs entirely. In an AI-driven threat landscape, any backlog becomes an open invitation as attackers move at machine speed.

Shift Zero embeds security into the operational flow, where threats originate, not downstream, where they explode. This calls for a fundamental restructuring of how security operates, moving from reactive to preventive and from human speed to machine speed. With Shift Zero, it’s no longer “we found a problem; now let’s fix it.” We now prevent problems from entering the system at all.

This requires three things:

The clearest example is security agents running as sidekicks to coding agents. As developers write code, a security agent validates and corrects it in real time so that vulnerabilities aren’t introduced. That's Shift Zero: as close to zero exposure as possible at all times.

5 focus areas

To operationalise this vision, we’re concentrating on five core areas:

  1. AI talent: We’re actively attracting and developing the finest AI minds globally. The centre serves as a home for specialised agentic AI researchers, adversarial AI engineers, and AI security architects who are rewriting the rules of defence.
  2. Groundbreaking innovation: We’re building the next-generation AI security stack. Our engineering focus is on autonomous security, creating AI that doesn’t just detect anomalies, but actively reasons through complex scenarios and takes immediate corrective action.
  3. An AI research epicentre: Grounded in production reality, the centre bridges theoretical breakthroughs with practical cybersecurity applications by using real-world evidence from enterprise AI deployments. Looking ahead, we aim to partner with elite academia and collaborate with the world's most advanced frontier AI models.
  4. Deep cyber knowledge and threat mastery: We’re developing absolute mastery over new, AI-powered threat methodologies. By understanding how adversaries exploit machine learning vulnerabilities, we’re building cybersecurity programs engineered to anticipate and neutralise AI-driven attacks before they ever occur.
  5. Global risk resilience: The centre serves as the definitive, battle-tested resource for global chief information security officers (CISOs) and risk leaders seeking a clear blueprint to transition their enterprises away from legacy risk frameworks and into robust, AI-first security postures.

AI for security and security for AI

As we pioneer this frontier, our research and development focus centres on a critical, two-sided coin: AI for security and security for AI. Navigating this duality is the only way to prevent modern enterprise innovation from devolving into operational chaos.

AI for security

Cybercriminals are already using AI to launch hyper-targeted, machine-speed attacks. The challenge for security teams is that the window between detection and exploitation is now measured in seconds, not hours.

Traditional, human-driven response can't match that velocity. We must deploy advanced AI models defensively to analyse behaviour patterns, anticipate adversarial shifts, and respond instantly at scale.

Security for AI

Deploying AI agents and large language models (LLMs) across an enterprise can introduce immense, unmapped risk. Left unchecked, autonomous agents can operate with dangerous leeway within your systems, accessing sensitive data, executing unapproved actions, and interacting with critical assets without proper supervision.

True enterprise protection requires keeping absolute, centralised control over your AI ecosystem.

Governance by design

True enterprise protection requires keeping absolute, centralised control over your AI ecosystem. Consider the stakes: A compromised or misconfigured agent in your environment can operate at machine speed.

As we've observed, an AI agent gaining unauthorised access can execute destructive commands in seconds, not hours. The only defence is governance by design. This necessitates three things:

CISOs deploying autonomous security must get this right from day 1: governance and control before velocity. Without it, a single misconfigured AI agent becomes a catastrophic risk.

Intelligence is useless without execution

Why does a platform-first, agentic approach matter for your organisation? Because in a world where security incidents continue to surge, an alert without an immediate workflow is just noise.

True cyber resilience calls for more than a shield; it demands an active, self-healing operating system. Because ServiceNow orchestrates the operational fabric of the modern enterprise, our autonomous security can intercept a threat, isolate a compromised machine or user identity, and patch a critical vulnerability automatically, right where the work happens.

The transition to autonomous cyber defence is inevitable. But here's the reality: Agentic AI is moving faster than governance frameworks can keep up. We're talking to enterprise leaders every day who are deploying AI agents into production and building their control models as they go, learning what works and what breaks in real time.

That's not failure; that's the stage we're in. The question isn't whether you have it perfect; it's whether you're learning from the people who've already hit the walls you're about to hit.

At the AI Centre for Cyber Defence, we're doing three things to help:

  1. Connecting you with peer CISOs managing actual agentic deployments, not theory
  2. Publishing research grounded in operational telemetry from live environments, not surveys or lab scenarios
  3. Aiding you to build governance models that don't just theoretically work, but they scale

The enterprises that move fastest won't be the ones with perfect controls. They'll be the ones learning from each other and adapting. Come join us. As a collaborative industry, we can go further faster.

We manage 175 million controls and prioritise 1 billion potential exposures daily across the global operations of our customers, including 90% of Fortune 500 companies. With 100 billion workflows orchestrated annually, we have an unparalleled understanding of how security actually works (and fails) in production. We're positioned to lead enterprises through their transition to AI-native, autonomous security.

Find out more about the AI Centre for Cyber Defence.