As the security community gathers at Black Hat USA 2026 in Las Vegas to confront increasingly sophisticated threat vectors, ServiceNow is making one thing unmistakable: We’re moving beyond legacy security models that struggle to keep pace with agentic businesses.
Following major architectural expansions, including the integration of Armis and Veza into the ServiceNow AI Platform to unify our security offering, we’ve established ServiceNow as the operational backbone for autonomous security.
At the foundation of this is our platform's ability to sense, decide, act, and secure across the entire enterprise—including identities, assets, vulnerabilities, and workflows—using a single, continuously updated plane and security graph.
This synthetic world model enables agentic security to operate with complete contextual awareness. It can understand an enterprise's ever-changing attack surface, which threats pose the greatest risk, and optimal remediation paths—all at machine speed.
To spearhead this operational revolution, I’m incredibly proud to lead the ServiceNow AI Center for Cyber Defense. This global hub is core to our security innovation engine with a mandate to pioneer the industry’s transition from reactive security to autonomous security.
The threat landscape has fundamentally changed. Attackers are weaponizing generative AI, compressing the timeline between vulnerability discovery and exploitation from months to minutes, according to Government Technology. Human-configured rules and static automation often can’t move fast enough to protect complex enterprise operations.
We’ve created the AI Center for Cyber Defense to completely flip the script. The center is entirely dedicated to mastering cutting-edge AI models and developing the agentic expertise needed to outpace and outsmart these new attack methods before they can disrupt business.
Building a paradigm-shifting center like this requires more than just advanced algorithms; it needs the sharpest minds. ServiceNow has systematically assembled a world-class cybersecurity "dream team."
By bringing together ServiceNow's proven security and risk leaders, made up of architects and practitioners who’ve built our platform's security foundation, with the elite founders, innovators, and engineering leadership from Armis and Veza, as well as CTCI, Silk Security, and OTORIO (previously acquired by Armis), we've created a unified powerhouse.
This combined brain trust has a track record of building disruptive technologies, identifying emerging threats, and scaling world-class platforms. With this collective of security practitioners, demonstrated innovators, validated entrepreneurs, and visionary technologists unified under the AI center mandate, we're positioned to scale this integrated model across the entire enterprise security landscape.
The center bridges the divide between deep AI engineering and practical, platform-wide cyber execution. We’re focusing our collective engineering muscle and extensive cyber knowledge to achieve Shift Zero, which helps eliminate vulnerability backlogs entirely. In an AI-driven threat landscape, any backlog becomes an open invitation as attackers move at machine speed.
Shift Zero embeds security into the operational flow, where threats originate, not downstream, where they explode. This calls for a fundamental restructuring of how security operates, moving from reactive to preventive and from human speed to machine speed. With Shift Zero, it’s no longer “we found a problem; now let’s fix it.” We now prevent problems from entering the system at all.
This requires three things:
- A complete context graph of the cyber landscape
- AI running continuous attack simulations
- Autonomous remediation at the source
The clearest example is security agents running as sidekicks to coding agents. As developers write code, a security agent validates and corrects it in real time so that vulnerabilities aren’t introduced. That's Shift Zero: as close to zero exposure as possible at all times.
To operationalize this vision, we’re concentrating on five core areas:
1. AI talent: We’re actively attracting and developing the finest AI minds globally. The center serves as a home for specialized agentic AI researchers, adversarial AI engineers, and AI security architects who are rewriting the rules of defense.
2. Groundbreaking innovation: We’re building the next-generation AI security stack. Our engineering focus is on autonomous security, creating AI that doesn’t just detect anomalies, but actively reasons through complex scenarios and takes immediate corrective action.
3. An AI research epicenter: Grounded in production reality, the center bridges theoretical breakthroughs with practical cybersecurity applications by using real-world evidence from enterprise AI deployments. Looking ahead, we aim to partner with elite academia and collaborate with the world's most advanced frontier AI models.
4. Deep cyber knowledge and threat mastery: We’re developing absolute mastery over new, AI-powered threat methodologies. By understanding how adversaries exploit machine learning vulnerabilities, we’re building cybersecurity programs engineered to anticipate and neutralize AI-driven attacks before they ever occur.
5. Global risk resilience: The center serves as the definitive, battle-tested resource for global chief information security officers (CISOs) and risk leaders seeking a clear blueprint to transition their enterprises away from legacy risk frameworks and into robust, AI-first security postures.
As we pioneer this frontier, our research and development focus centers on a critical, two-sided coin: AI for security and security for AI. Navigating this duality is the only way to prevent modern enterprise innovation from devolving into operational chaos.
Cybercriminals are already using AI to launch hyper-targeted, machine-speed attacks. The challenge for security teams is that the window between detection and exploitation is now measured in seconds, not hours.
Traditional, human-driven response can't match that velocity. We must deploy advanced AI models defensively to analyze behavior patterns, anticipate adversarial shifts, and respond instantly at scale.
Deploying AI agents and large language models (LLMs) across an enterprise can introduce immense, unmapped risk. Left unchecked, autonomous agents can operate with dangerous leeway within your systems, accessing sensitive data, executing unapproved actions, and interacting with critical assets without proper supervision.
True enterprise protection requires keeping absolute, centralized control over your AI ecosystem. Consider the stakes: A compromised or misconfigured agent in your environment can operate at machine speed.
As we've observed, an AI agent gaining unauthorized access can execute destructive commands in seconds, not hours. The only defense is governance by design. This necessitates three things:
- A complete cybersecurity plane, including assets, identities, vulnerabilities, workflows, and business context, so that you know exactly what each AI agent can access and what it's doing
- Deterministic governance guardrails that help prevent AI agents from exceeding their intended scope, with continuous audit logging
- Automated quality assurance and control mechanisms that verify AI agent actions in real time, with rollback capability if an agent deviates from its authorized behavior
CISOs deploying autonomous security must get this right from day 1: governance and control before velocity. Without it, a single misconfigured AI agent becomes a catastrophic risk.
Why does a platform-first, agentic approach matter for your organization? Because in a world where security incidents continue to surge, an alert without an immediate workflow is just noise.
True cyber resilience calls for more than a shield; it demands an active, self-healing operating system. Because ServiceNow orchestrates the operational fabric of the modern enterprise, our autonomous security can intercept a threat, isolate a compromised machine or user identity, and patch a critical vulnerability automatically, right where the work happens.
The transition to autonomous cyber defense is inevitable. But here's the reality: Agentic AI is moving faster than governance frameworks can keep up. We're talking to enterprise leaders every day who are deploying AI agents into production and building their control models as they go, learning what works and what breaks in real time.
That's not failure; that's the stage we're in. The question isn't whether you have it perfect; it's whether you're learning from the people who've already hit the walls you're about to hit.
At the AI Center for Cyber Defense, we're doing three things to help:
- Connecting you with peer CISOs managing actual agentic deployments, not theory
- Publishing research grounded in operational telemetry from live environments, not surveys or lab scenarios
- Aiding you to build governance models that don't just theoretically work, but they scale
The enterprises that move fastest won't be the ones with perfect controls. They'll be the ones learning from each other and adapting. Come join us. As a collaborative industry, we can go further faster.
We manage 175 million controls and prioritize 1 billion potential exposures daily across the global operations of our customers, including 90% of Fortune 500 companies. With 100 billion workflows orchestrated annually, we have an unparalleled understanding of how security actually works (and fails) in production. We're positioned to lead enterprises through their transition to AI-native, autonomous security.