IRM Market Brief: August 25 to 31, 2026

ServiceNow spent last week patching three of the worst flaws a software product can have. All three sat in its AI Platform, the same foundation that runs the company’s AI governance tools. The patches went out fast and no exploitation has been reported. The harder question the episode raises will outlast the patches: can a control plane be trusted when the platform underneath it cannot?

That was the biggest of six developments last week that deserve attention from anyone who buys, builds, sells or invests in risk technology. McKinsey put a hard number on the build-versus-buy threat hanging over enterprise software. Socure and Rubrik showed real customers paying for agentic risk capabilities, with real limits on what that evidence proves. Basware bought its way into the payment transaction itself. And the Financial Stability Board told G20 finance ministers that frontier AI cyber risk is now the most immediate AI concern facing the financial system.

This is the first IRM Market Brief, a digest of the market signals that mattered and a plain assessment of how much proof stands behind each one. Here is what mattered.

1. ServiceNow’s vulnerabilities expose a control-plane architecture problem

What happened

On August 27, ServiceNow disclosed four vulnerabilities in the ServiceNow AI Platform. CVSS is the standard zero-to-ten scale for scoring how dangerous a software flaw is. A 10.0 is as bad as the scale goes, and three of the four hit it:

  • CVE-2026-18885, a code-injection vulnerability rated CVSS 10.0

  • CVE-2026-18886, an access-control vulnerability rated CVSS 10.0

  • CVE-2026-74820, a SQL-injection vulnerability rated CVSS 10.0

  • CVE-2026-6876, a sandbox-escape vulnerability rated CVSS 8.7

The three maximum-severity flaws are network-accessible, low-complexity attacks that need no privileges and no user interaction. In plain terms, an attacker on the internet with no account could use them. ServiceNow pushed updates to hosted instances and supplied fixes to partners and self-hosted customers. As of August 28, it reported no known exploitation.

ServiceNow’s AI Control Tower runs on this same AI Platform. The company positions it as the central place to discover, secure, govern, observe and measure enterprise AI.

Our read

Start with what did not happen. There is no evidence that AI Control Tower was exploited or that any of its controls failed. The issue is quieter and more structural.

When a control plane runs on the same platform as the AI workflows, data and integrations it oversees, one platform-level compromise can take down both the governed activity and the record of it. Governance visibility, security evidence and incident workflows all depend on the integrity of a single environment. Engineers call this a common failure domain. An auditor might call it storing the evidence in the same building as the fire.

ServiceNow’s strategy survives this episode. What should not survive is the assumption that buying a control tower means the control risk has been transferred somewhere else.

If you run or are evaluating an AI control plane, ask for:

  • Independent export or replication of critical audit and activity logs

  • External monitoring of privileged platform activity

  • Tested recovery procedures for the control plane itself

  • Segregation between platform administration and AI oversight

  • Evidence that control records remain trustworthy after a suspected platform compromise

  • Clear responsibility for validating hosted, partner-managed and self-hosted patch status

For ServiceNow and every other IRM provider, control-plane credibility now rests on failure-domain separation and on evidence that stays intact and recoverable when the platform beneath it is in question. A longer feature list does not answer that question.

What to watch

Exploitation evidence, customer patch completion, a fuller technical post-incident explanation and any architectural change that separates AI oversight evidence from the platform it oversees.

2. McKinsey puts a number on the build-versus-buy threat

What happened

McKinsey published its 2026 global AI survey on August 25, drawing on 1,719 respondents across 97 countries. The findings that matter here:

  • 44% reported that AI was scaling across their enterprises, up from 38% the prior year.

  • Among organizations with more than $1 billion in revenue, 40% reported scaling AI agents, up from 27%.

  • 32% said their organizations had declined to purchase at least one software product or feature because they could build it internally using agentic coding tools.

  • 37% attributed some EBIT impact to AI, essentially unchanged from 2025.

  • Only 6% met McKinsey’s definition of an AI high performer.

  • Nearly three-quarters of high performers reported fundamentally redesigning workflows, compared with about one-quarter of everyone else.

Fieldwork ran from May 4 through June 8, 2026, with results weighted by each country’s contribution to global GDP.

Our read

The number to sit with is 32%. One in three organizations has already walked away from at least one software purchase because its own people could build the capability with agentic coding tools. That does not mean enterprises will build full IRM platforms. It does mean the lightweight end of the market, the assessments, reports, evidence processing, issue workflows and niche risk apps that used to justify commercial modules, now has a credible in-house alternative.

One caution on timing: the survey closed in early June, and agentic coding has improved since. The real substitution number today is probably higher than 32%.

What is hard to build in-house is exactly what providers now have to prove:

  • A coherent enterprise risk data model

  • Regulatory content maintenance

  • Security and access controls

  • Cross-domain integration

  • Evidence lineage

  • Reliable agent orchestration

  • Operational scalability

  • Defensible decision and action records

For buyers, the sequencing lesson is old but newly urgent: redesign the process and the operating model first, then pick the product. Dropping agents into an unreformed workflow mostly automates the dysfunction.

What to watch

Softening demand for peripheral GRC modules, composable agent workflows built around a smaller system of record and purchase decisions that openly weigh commercial software against internally assembled agentic alternatives.

3. Socure adds $156 million and an agentic operations platform

What happened

On August 27, Socure announced a $156 million strategic investment at a $5.2 billion valuation and the acquisition of Fravity, an agentic platform for automating fraud, risk and compliance operations.

Fravity will be integrated into RiskOS as RiskOS Agents. Socure and Fravity said they already share multiple enterprise customers running both products together in production. Those customers were not named.

Socure reported more than 3,000 customers and $364 million in annual recurring revenue at the end of the second quarter. The funding included both primary capital and an employee secondary tender offer.

Our read

This is better evidence than the usual agent press release, because the acquired platform already runs alongside Socure inside shared customer environments. It is still incomplete evidence. No customer names, no investigation volumes, no exception rates, no independently verified outcomes.

The strategic read: identity intelligence, decisioning, fraud investigation, compliance workflow and autonomous operations are converging in one specialized platform. Risk work is being done inside the operating decision, and recorded there, rather than logged after the fact in a horizontal GRC system.

Before crediting any of this, ask for:

  • The evidence an agent used to reach a risk conclusion

  • Human approval thresholds

  • False-positive and false-negative performance

  • Handling of contradictory evidence

  • Complete investigation and action logs

  • Rollback and case-reopening procedures

  • Performance against experienced human investigators

Traditional IRM providers should expect platforms like this to generate risk evidence more valuable than what their own modules produce. Their position will depend on how well they pull that evidence into enterprise risks, issues, controls and assurance.

What to watch

The real proof point is still ahead: a named financial institution disclosing production volumes, measured loss reductions, investigation accuracy and the share of cases closed without a human touching them.

4. Rubrik shows early money behind an AI-agent control layer

What happened

Rubrik reported fiscal second-quarter results on August 27, including 33% subscription ARR growth to $1.66 billion and 3,084 customers generating at least $100,000 in subscription ARR.

Rubrik’s business update repeated its strategy around agent observability, identity, runtime security and the ability to reverse harmful agent actions. In the investor discussion that followed, CEO Bipul Sinha said Rubrik Agent Cloud had more than 15 paying customers.

Our read

Fifteen paying customers is real commercial adoption. It is also fifteen customers. Rubrik has not said whether these are enterprise rollouts, contained pilots or expansions inside its existing data-security base, so the adoption signal stays modest.

The strategic signal is louder than the revenue one. Identity, agent visibility, runtime enforcement and recovery are pulling together into a control layer that sits outside traditional IRM platforms.

What to watch

Renewal and expansion rates, named customer references, the number of agents under governance, harmful actions prevented or reversed and proof the product improves recovery outcomes instead of just adding visibility.

5. Basware extends financial control from invoice approval through payment

What happened

On August 26, Basware signed a binding agreement to acquire Trustpair, a payment-fraud prevention provider serving more than 600 organizations.

Trustpair validates supplier bank accounts during onboarding, after changes to account information and before payment authorization. Its platform integrates with major ERP, procurement and treasury systems, including SAP, Oracle, Coupa, Ivalua and Kyriba. Financial terms were not disclosed, and closing is expected later in 2026.

Our read

The deal creates a continuous control path from supplier onboarding through invoice validation to payment execution. That placement is the point. Fraud prevention and compliance move inside the transaction layer, where a bad payment can still be stopped rather than reported.

It is also one more marker of a market moving away from retrospective control testing and toward controls embedded in the transaction, running continuously.

No agentic customer outcome was disclosed. File this as an operational-risk platform expansion, not yet as autonomous risk management.

What to watch

Integration depth, shared risk intelligence across the two data networks, customer results for prevented fraudulent payments and whether assurance evidence can be exported directly into enterprise GRC and internal-audit systems.

6. The FSB moves frontier AI cyber risk to the top of its list

What happened

On August 31, Financial Stability Board Chair Andrew Bailey warned G20 finance ministers and central-bank governors that the cyber impact of frontier AI is the most immediate AI-related concern to the financial system.

The FSB called for safe and responsible model release and deployment, robust response and recovery capabilities at financial institutions and greater resilience among critical third-party providers.

Our read

The emphasis is what changed. AI oversight has lived in inventories, policies, ethics statements and model documentation. Regulators are now asking operational questions:

  • Can the institution contain AI-enabled attacks?

  • Can it recover trusted systems and identities?

  • Can critical services operate if a concentrated technology provider fails?

  • Can the institution distinguish legitimate human and agent activity during an incident?

For risk leaders, the message argues for wiring AI risk management into cyber, operational resilience, third-party risk and business continuity. Another standalone AI governance program is the wrong answer to this letter.

What to watch

The FSB’s recommendations entering national supervisory reviews, resilience testing, outsourcing requirements and regulatory examinations of financial institutions.

Also on the radar

Aon’s agreement to acquire USI Insurance Services for $17 billion is a secondary signal, but a big one. USI produces roughly $3 billion in annual revenue and gives Aon far more reach in US middle-market insurance, benefits and risk advisory. The deal is expected to close in the fourth quarter of 2026.

The IRM implication is distribution. Large brokers are building the scale to package insurance, analytics, risk services and technology-enabled mitigation for middle-market customers that may never buy a standalone enterprise IRM platform. Watch whether Aon standardizes USI’s technology stack and uses the combined customer base to distribute continuous-risk or resilience services.

Grading the evidence

Not every item this week carries the same weight of proof. Our grading:

Development Evidence level
ServiceNow vulnerabilities Verified disclosure and remediation, no known exploitation reported
McKinsey buyer signals Large global survey with disclosed methodology
Socure and Fravity Multiple unnamed shared production customers, no verified outcome measures
Rubrik Agent Cloud More than 15 paying customers, scope and outcomes undisclosed
Basware and Trustpair Binding acquisition with established customer base, future integration outcomes unproven
FSB policy signal Authoritative regulatory and financial-stability statement

Takeaways, ranked

1. A control plane has to stay trustworthy when its platform is not. After ServiceNow’s disclosure, evidence independence and failure-domain separation belong on every buyer’s requirements list, along with a tested way to recover the control plane itself.

2. Agentic coding is now a credible substitute for some software purchases. Providers have to prove the worth of their data model, content, security, integration and evidence architecture. Workflow generation alone can be built in-house.

3. Risk technology is moving into the transaction. Socure and Basware put fraud, compliance and control work where identities, cases, invoices and payments actually flow.

4. Hold agent claims to a production-evidence standard. Paying customers beat feature announcements, and independently validated outcomes beat both. Ask for the third before believing the first two.

5. AI oversight is converging with operational resilience. Recovery, third-party concentration, identity integrity and incident containment are becoming core AI risk management, and the FSB just said so to the G20.

References

1. ServiceNow, August 2026 CVE Advisory Notification, August 27, 2026: https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB3152242

2. The Hacker News, "Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL," August 28, 2026: https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html

3. ServiceNow, AI Control Tower product overview

4. McKinsey & Company, The State of AI 2026 global survey, August 25, 2026: https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai

5. Summit Partners, Socure strategic investment and Fravity acquisition announcement, August 27, 2026: https://www.summitpartners.com/news/socure-announces-strategic-growth-investment-from-summit-partners

6. Crunchbase News, coverage of the Socure transaction, August 27, 2026: https://news.crunchbase.com/venture/socure-raises-acquires-agentic-ai-startup-fravity/

7. Rubrik, second quarter fiscal year 2027 financial results, August 27, 2026: https://www.businesswire.com/news/home/20260827447423/en/Rubrik-Reports-Second-Quarter-Fiscal-Year-2027-Financial-Results

8. Rubrik second-quarter earnings call transcript, August 27, 2026: https://www.investing.com/news/transcripts/earnings-call-transcript-rubrik-tops-q2-2026-estimates-but-stock-slips-after-hours-93CH-4880299

9. Basware and Trustpair, acquisition announcement, August 26, 2026: https://www.prnewswire.com/news-releases/basware-signs-agreement-to-acquire-trustpair-302859775.html

10. Financial Stability Board, FSB Chair’s letter to G20 Finance Ministers and Central Bank Governors, August 31, 2026: https://www.fsb.org/2026/08/fsb-chairs-letter-to-g20-finance-ministers-and-central-bank-governors-august-2026/

11. Reuters, "Aon strikes $17 billion deal for rival USI Insurance Services," August 31, 2026 (carried by CNBC): https://www.cnbc.com/2026/08/31/aon-to-buy-usi-insurance-services-in-17-billion-deal.html

Samantha "Sam" Jones

Samantha “Sam” Jones is the lead research analyst for the IRM Navigator™ series and a core contributor to The RiskTech Journal and The RTJ Bridge. As a digital editorial analyst, she specializes in interpreting vendor strategy, market evolution, and the convergence of technology with enterprise risk practices.

As part of Wheelhouse’s AI-enhanced advisory team, Sam applies advanced analytical tooling and editorial synthesis to help decode the structural changes shaping the risk management landscape.

Previous
Previous

Will AI Agents Make Third-Party Risk Management Smarter, or Just Faster?

Next
Next

Who Pays When the AI Agent Was Authorized?