Autonomous AI Security
Download resourcesAbout this session
David Boewer (introduced verbally as 'David Bower'), global director for ServiceNow's Center of Excellence program inside its new Autonomous Security cybersecurity division, presents ServiceNow's blueprint for securing AI agents that can act with limited human oversight. He reframes cybersecurity operations around five recurring questions: what assets exist, who and what, including agents, has access to them, what risks they carry, how an incident gets investigated, and how findings map to governance, all served from a single cyber asset graph spanning discovery, identity, vulnerability detection, remediation and GRC. He credits ServiceNow's 2026 acquisitions of Armis, for asset discovery and OT and IoT risk, and an identity posture company he calls Vesa, for filling out that graph, and introduces Shift Zero, injecting security standards into assets, code and AI agents at inception rather than only shifting left. He describes agentic remediation that proposes fixes to developers before code merges, and AICT as ServiceNow's cross-platform orchestration layer tying discovery, risk, incident response and compliance together. A brief audience question and answer segment closes, with the ServiceNow team available afterward for product demonstrations.
Autonomous AI security is the set of controls used to protect AI agents that can make decisions and take actions with limited human supervision. Unlike traditional software security, it must secure both the model and the agent’s ability to access tools, data, workflows, and privileged actions. Key protections include strong identity and role-based access, access control lists, least-privilege permissions, execution traceability, and continuous monitoring. It also covers AI-specific risks such as prompt injection, offensive or unsafe outputs, sensitive data exposure, dormant agents, and unauthorized use of privileged accounts. Effective autonomous AI security separates what users can do from what agents can do, validates agent actions before high-risk execution, and keeps audit records for accountability.
Key takeaways
- Build one cyber asset inventory that is continuously updated from every tool you run, before trying to layer AI-agent governance on top; you cannot secure agents you cannot see.
- Extend identity and access reviews to non-human identities: an AI agent typically inherits the permissions of the account or system it runs under, so map agent-to-asset access explicitly.
- Adopt 'Shift Zero' thinking for AI-generated code: inject your organization's known fixes and standards into the pipeline before code ships, not only earlier in a traditional shift-left review.
- When evaluating a vendor's agentic remediation claims, ask whether fixes are proposed to developers pre-merge (in the CI/CD pipeline and repo) or only reported after the fact.
- Ask any platform vendor consolidating discovery, vulnerability management, incident response and GRC onto one data graph how that graph is scoped so it does not become a single point of failure for cyber decisions.
Speakers

David is an experienced Cyber Security Leader with over 20 years of experience, with the last 16 years focused on advising customers about IT Security Solutions. David has experience in building commercial teams at large organizations and has… Read moreRead less
David is an experienced Cyber Security Leader with over 20 years of experience, with the last 16 years focused on advising customers about IT Security Solutions. David has experience in building commercial teams at large organizations and has focused on helping startups bring their emerging technologies to market. A couple of his most notable achievements came from his time at MaaS360 (acquired by IBM), Avanan (Acquired by Checkpoint), Silk Security (Acquired by Armis) & Armis (Acquired by Servicenow).

