What ServiceNow Just Announced Is Bigger Than a Security Story

ServiceNow Chairman and CEO Bill McDermott presents the AI Control Tower architecture during the Knowledge '26 opening keynote on May 5, 2026, in Las Vegas. The architecture organizes enterprise AI workflows around four operational motions (Sense, Decide, Act, Secure) with the AI Control Tower as the governance surface beneath them. Photo by John A. Wheeler.


ServiceNow announced Autonomous Security and Risk on Tuesday morning, integrating its recent acquisitions of Armis and Veza into the ServiceNow AI Platform under what the company calls the AI Control Tower. The press release framed the launch as a way to govern every AI agent, identity, and connected asset across the enterprise. I am writing from Knowledge ’26 in Las Vegas, where the announcement landed in the opening keynote and where the architectural ambition behind it has been on display all week.

The first-wave coverage is reading the announcement as a security story. The Armis acquisition closed two weeks ago, the Veza integration extends identity controls to the AI agents now operating inside enterprises, and a new generation of what ServiceNow calls AI specialists handles vulnerability remediation and security operations end to end. Those elements are real, and the security framing is not wrong. It is incomplete. What ServiceNow has actually announced is the first complete commercial architecture for governing the autonomous enterprise. We have been writing about the emergence of this category, autonomous integrated risk management (IRM), in The RiskTech Journal (RTJ) since October 2024.

What Was Announced

The Autonomous Security and Risk dashboard shows AI specialists assigned to vulnerability resolution, security operations, and third-party screening, with active task counts and compliance posture metrics rendered as a unified governance surface. Image captured at the Knowledge '26 demonstration zone, May 5, 2026.

The most visible piece of the announcement is a set of AI specialists that operate as digital workers. They are assigned to teams the way a human employee would be, with defined roles and responsibilities. The first wave handles phishing incident response, vulnerability remediation, and third-party risk screening. They work alongside human teams with full traceability on every action they take. ServiceNow’s own security operations team is reportedly running on the platform and handling incidents seven times faster than under prior workflows.

What makes the announcement bigger than a security product is what sits underneath those AI specialists. The AI Control Tower inventories every AI agent operating in an enterprise, scores its risk continuously, enforces appropriate access controls in real time, and produces an audit trail that regulators and auditors can accept. Armis brings real-time visibility into every connected asset across information technology, operational technology, internet-connected devices, medical equipment, and cloud workloads. Veza brings a complete map of who and what has access to what across the enterprise, including the AI agents now acting under permissions that were originally designed for humans.


NVIDIA founder and CEO Jensen Huang, ServiceNow Chairman and CEO Bill McDermott, and ServiceNow Vice Chairman Nick Tzitzon discuss the NVIDIA and ServiceNow partnership during the Knowledge '26 keynote on May 5, 2026. The architecture displayed behind them shows the AI Control Tower at the top with its five risk management functions (Discover, Observe, Govern, Secure, Measure), positioned above the ServiceNow Autonomous Workforce, the Action Fabric, the Project Arc enterprise agent operating system, and the NVIDIA infrastructure components that form the underlying stack. Photo by John A. Wheeler.

ServiceNow also opened the architecture to AI agents built outside its own platform. Through a new connector called the Action Fabric, third-party AI agents can execute governed enterprise actions through ServiceNow’s workflows. Anthropic’s Claude was among the first design partners. The architecture is not a closed system limited to ServiceNow’s own AI.

ServiceNow also extended its partnership with NVIDIA, integrating the NVIDIA AI infrastructure stack underneath the AI Control Tower. Wheelhouse Advisors raised the strategic question in our April 7 RTJ Bridge OnWatch research note "NemoClaw and the Trillion-Dollar Tailwind for Autonomous IRM," asking whether proprietary governance architecture would remain a differentiating premium as open agent infrastructure matured, and watching specifically for ServiceNow's NemoClaw positioning within ninety days of NVIDIA's GTC 2026 announcement. ServiceNow's answer at Knowledge '26 is that proprietary governance remains the differentiating premium, but only when it sits on top of open infrastructure rather than alongside it. The AI Control Tower is proprietary; the agent infrastructure underneath it is open and partnership-based.

The customer outcomes ServiceNow disclosed are substantial. A global energy company operating across more than seventy countries saved 1.2 million hours by automating security operations and reduced threat containment time by 97 percent. A major United States bank eliminated 96 percent of its dormant non-human identities, which is the kind of access cleanup that has historically taken years. A Fortune 100 aerospace manufacturer reduced control attestation time by 75 percent and compliance gap closure time by 85 percent. These outcomes were produced in the early months of an architecture that has been generally available for one full quarter.

The Knowledge ’26 keynote also introduced Autonomous CRM, a separate product that applies the same architectural pattern to sales automation, customer support, and customer self-service. The same Sense, Decide, Act, Secure motion that runs autonomous security and risk also runs autonomous customer relationship management. The AI Control Tower governs both. That is the signal that the AI Control Tower is not a security product. It is the governance layer for autonomous AI across the enterprise.

What It Means for the Risk Technology Market

For senior leaders responsible for risk, compliance, and audit, the implications are immediate. The questions you will be asking your technology vendors are different now than the questions we were asking when we began covering autonomous IRM. Can the platform inventory autonomous AI agents the way it inventories your employees and physical assets? Can it govern access for AI agents at the same level of rigor as your human users? Can it produce the kind of evidence regulators and auditors will accept under the new AI standards now coming into force, including ISO/IEC 42001, the NIST AI Risk Management Framework, and the EU AI Act? Can it operate at the speed AI operates, which is no longer the speed of quarterly risk reviews and annual control testing?

These questions cut across the existing risk and compliance technology market. Some vendors will rise to meet them. Others were built for a different era and a different problem. Wheelhouse Advisors has been tracking vendor readiness for this transition for more than a year through our IRM50 AI Disruption Risk Index, which assesses fifty leading risk technology vendors against the architectural shift now underway. The Index has been signaling for some time that this transition was coming. ServiceNow has now made it concrete.

The implication for buyers is straightforward. Vendor selection over the next twelve months is no longer a comparison of features at the workflow level. It is a choice between platforms architected for an enterprise where AI agents act autonomously and platforms architected for an enterprise where humans do most of the work. Those are different platforms. They produce different outcomes for the businesses that buy them.

What It Means for the AI Buildout in the Enterprise

The broader implication runs well beyond risk technology. AI agents are entering enterprises at a pace no governance program designed for human workflows can absorb. The non-human identities behind those agents already vastly outnumber human ones in many environments, and the agents acquire access, make decisions, and execute actions at machine speed. The question is no longer how to slow the agents down. The agents will not slow down. The question is how to govern them at the speed they operate, with the accountability that boards, regulators, and customers require.

ServiceNow’s announcement is one answer to that question. It will not be the only answer. Other major technology vendors with the right architectural building blocks and the ambition to assemble them will follow, with different design choices and different strengths. The autonomous enterprise is not a single-vendor outcome. But ServiceNow has now established a reference architecture, and every subsequent vendor announcement will be evaluated against it.

The deeper shift the announcement signals is about how risk management itself is evolving inside the enterprise. For decades, risk management was an adjacent function. Companies bought risk technology from specialty vendors, deployed it within compliance and audit programs, and treated it as overhead against revenue-generating activity. ServiceNow’s architecture suggests a different future. Every business has become a technology company in the sense that software is now the operational foundation of how value gets created. ServiceNow’s announcement points toward a parallel shift in which every business becomes a risk management company, in the sense that governance becomes the operational foundation of how AI gets deployed at scale.

That is a transition CEOs, CFOs, CIOs, and boards will recognize, because they have been through the technology version of it. Risk and compliance leaders will be on the front line of executing the shift, but the strategic implications belong to the senior team.

What Comes Next

Wheelhouse Advisors will publish a detailed analytical treatment of ServiceNow’s announcement as an RTJ Bridge research note on Tuesday, May 12. That research note maps ServiceNow’s architecture in detail, engages the relevant standards at the level of specific requirements rather than framework names, identifies the leading vendors positioned to compete in this transition along with their architectural strengths and limitations, and addresses the dimensions of ServiceNow’s announcement that have not yet been proven at scale.

For readers who want the broader governance argument that frames why ServiceNow’s announcement matters, the May 4 RTJ Bridge research note “Governing AI at the Speed of AI” is the foundation. It establishes why human-paced governance cannot keep up with autonomous AI agents and what an architecture that operates at AI speed actually requires.

The questions are different now than they were when we began covering autonomous IRM, and now that autonomous IRM has fully entered the marketplace, the questions will become more urgent and more consequential. The RTJ Bridge is Wheelhouse Advisors’ subscription research platform that connects our public RTJ articles to our full complement of IRM Navigator research reports. It is where senior risk technology buyers and investors find the analytical work they need to evaluate the autonomous transition in real time, including both RTJ Bridge research notes referenced above and the research that follows. It is available at wheelhouseadvisors.com/rtj-bridge.

John A. Wheeler

John A. Wheeler is the founder and CEO of Wheelhouse Advisors, a global risk management strategy and technology advisory firm. With over three decades of experience spanning executive management, finance, risk management, audit, and IT, John is a world-renowned expert in integrated risk management technology, executive leadership, and corporate governance.

https://www.linkedin.com/in/johnawheeler/
Previous
Previous

Why Your ERM Program Cannot Get a Seat at the Strategy Table

Next
Next

Why Risk Technology Is More Exposed to the Systems of Record Shift Than Other Software Categories