ServiceNow announced the launch of Autonomous Security & Risk to govern AI agents, identities, and connected assets during its Knowledge 2026 event in Riyadh. The platform integrates technologies from Armis and Veza to address security, risk, and compliance requirements in enterprise environments.
Security and risk solutions crossed $1 billion in annual contract value for ServiceNow last year. Consequently, this sector has become one of the fastest-growing sources of demand on the company’s platform. This growth occurs as artificial intelligence increases the number of identities, permissions, and connected assets requiring governance.
“Today’s CISOs have to operate at two speeds: neutralizing threats in real time while reporting risk to the board with conviction. Autonomous Security & Risk replaces that fragmented stack with a single graph that maps every identity, every permission, and every connected asset, so prevention, detection, and response happen at machine speed.”
John Aisien, Senior Vice President and General Manager, Central Product Management, Security & Risk, ServiceNow
Integrating Armis and Veza
The integration of Armis provides real-time, contextual awareness of connected cyber assets across IT, operational technology, and IoT environments. Specifically, Armis monitors network traffic without agents and enriches asset records with device classifications and risk postures. This data flows directly into the ServiceNow Configuration Management Database to update the visible attack surface.
Managing Non-Human Identities
Meanwhile, Veza’s Access Graph maps access relationships across enterprise environments to govern both human and non-human identities. This integration helps organizations enforce least-privilege access and trigger remediation workflows. Notably, non-human identities associated with AI agents now outnumber human identities within many enterprises.
Deploying Autonomous Security & Risk
Organizations deploying Autonomous Security & Risk can use new AI specialists to handle vulnerability resolution and security operations. These tools autonomously address unresolved vulnerability backlogs and investigate phishing incidents alongside human teams. Furthermore, the system scores agent risks in real time to prevent configuration drift.
Measurable Enterprise Outcomes
Several organizations have reported operational improvements using these integrated tools. For instance, a global energy company operating in over 70 countries saved 1.2 million hours by automating cybersecurity operations. Additionally, a major financial institution eliminated 96% of dormant non-human identities, while an aerospace manufacturer reduced control attestation times by 75% in the economy sector.





