---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# AI Security Exposure Management

# Exploring AI Security Exposure Management {#ariaid-title1}

* Release version: Australia
* 
* Updated August 3, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 4 minutes to read

Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Exploring AI Security Exposure Management

AI Security Exposure Management is a component of the Unified Security Exposure Management suite designed to help ServiceNow customers manage AI-related security risks in their environments.
As AI adoption grows, new attack surfaces emerge, including vulnerabilities in open source AI models, harmful AI model behaviors, and AI infrastructure configuration issues.
This solution integrates with third-party AI security tools to identify and manage these exposures effectively.
Show full answer Show less  
The application supports importing AI vulnerabilities, validation findings, and configuration posture issues into the ServiceNow AI Platform® instance, providing comprehensive visibility and control over AI security risks.

## Key Features

* **AI Exposure Identification:** Detects AI vulnerabilities in models, AI validation findings from automated penetration testing (such as PII leakage), and AI posture findings related to configuration issues in AI assets.
* **Third-Party Integrations:** Connects with external AI security tools and imports findings via Service Graph Connectors to maintain an up-to-date AI asset inventory in the CMDB.
* **Guardrails Detection:** Utilizes AI skills to map runtime protection policies (guardrails) to AI validation findings, enabling analysts to identify mitigated risks and automate deferral of low-risk exposures.
* **Prioritization and Workflow Automation:** Helps vulnerability managers prioritize high-risk AI exposures and defer those with existing mitigations, optimizing remediation workflows and reducing mean time to remediate.
* **MITRE ATLAS Integration:** Associates findings with MITRE ATLAS tactics and techniques, enhancing context and aiding in risk analysis and response planning.
* **Role-Specific Use:** Designed for vulnerability analysts, managers, and CISOs to monitor AI risk posture, assign remediation tasks, and deliver actionable dashboards and reports.

## Key Outcomes

* **Enhanced Visibility:** Provides a dedicated AI Exposures module within the Security Exposure Management workspace for comprehensive insight into AI security threats.
* **Efficient Risk Management:** Enables organizations to manage the AI attack surface by identifying vulnerabilities, behavioral risks, and configuration issues across AI assets.
* **Improved Remediation:** Automates deferral of mitigated findings and focuses remediation efforts on high-risk exposures, helping teams reduce response times and optimize resource allocation.
* **Streamlined Reporting:** Offers dynamic dashboards and reports that communicate AI security posture and remediation progress to stakeholders, supporting informed decision-making.

## Next Steps for ServiceNow Customers

To effectively implement and use AI Security Exposure Management, customers should explore:

* Installation and configuration of the AI Security Exposure Management application.
* Using the AI guardrails helper skill and agentic workflows to understand findings and associated mitigations.
* Viewing AI Exposures in the workspace to monitor risks.
* Configuring remediation task rules to automate and prioritize remediation efforts.  
AI Security Exposure Management is a part of the Unified Security Exposure Management product suite of applications. AI Security Exposure Management integrates with third-party AI security products to help you manage various types of potential AI exposure across your
environment.

## AI Security Exposure Management overview {#exploring-ai-security-exposure__cf-exploring-parent-overview}

With the rapid growth and adoption of AI in enterprises, a new attack surface is emerging in the form of AI security exposures. This attack surface includes open source AI model vulnerabilities and AI model behavioral risks with
harmful prompts that might result in security breaches and data loss during runtime. Additionally, AI infrastructure configuration issues might exist in AI agents, data sets, or any other type of AI assets in your environment.

You organization can efficiently manage AI security exposures such as AI model vulnerabilities, harmful AI model behavior, and AI infrastructure configuration issues with AI Security Exposure Management.

Identify existing guardrails that might mitigate some of the AI validation findings that indicate risky behavior of an AI application or model with the [Guardrails Detector skill](https://servicenow-prod.fluidtopics.net/FQmdvLEryKFp8nI8GejSPA "You have the option to use a generative AI skill and agentic workflow to help you understand what type of findings you have, understand the guardrails associated with findings, and see why the skill mapped guardrails to particular findings.").

Automate the deferral of findings that have mitigations or guardrails and create exception rules to auto-defer future findings with an [agentic workflow](https://servicenow-prod.fluidtopics.net/iQh3Vd3kjtg5IXKa1bucAw "Use the AI agent to ask about guardrails identified by the AI skill component in the AI Guardrails Helper. Automatically defer findings with existing mitigations in the form of guardrails and create exception rules to automatically defer future findings.").

With AI Security Exposure Management, vulnerability managers prioritize high risk exposures and defer low risk exposures that might have mitigations or guardrails already in place. This prioritization ultimately helps vulnerability
management teams optimize remediation workflows to help them reduce the meantime to remediate their high risk exposures.

## Key terms for AI Security Exposure Management {#exploring-ai-security-exposure__section_wql_2zv_w3c}

Navigate to WorkspacesSecurity Exposure ManagementAI Exposures.  

AI vulnerabilities
:   Vulnerabilities that are discovered in open source AI models that are published in repositories.
    Third-party integrations perform static scans of AI models for these vulnerabilities. The findings (AISF) generated by this application are generally open source, but other models such as self-hosted models are also supported. A
    finding is created when a known model vulnerability or behavior can be matched to an AI model (asset) in your CMDB.  
    The following types of findings are generated and maintained AI Security Exposure Management (AISEC):

    * AI Vulnerability Finding (AIVUL)
    * AI Validation Finding (AIVF)
    * AI Posture Finding (AIPF)
    {#exploring-ai-security-exposure__ul_vct_qg4_djc}

AI validation findings
:   Findings from third-party automated penetration testing or automated red teaming done to verify the behavior of AI applications or models by validating them against their prompt libraries. For example, third-party vendors test AI
    applications for issues like Personally Identifiable Information (PII) leakage.

AI posture findings
:   Configuration issues in AI agents, tools, prompts, MCP servers that are detected by third-party AI security tools in various platforms such as Microsoft Copilot Studio, AWS, and others.

Service Graph Connector
:   Type of third-party integration that imports AI inventory data into your CMDB.

AI security exposure management integrations
:   Third-party integrations that import AI vulnerabilities, validation findings, and posture or configuration findings from AI security tools into tables in your ServiceNow AI Platform® instance.

Guardrails detection

:   AI security platforms support runtime protection policies or guardrails that can detect AI behavior risks
    such as sensitive information disclosure and block or redact the content in the payload.

    ServiceNow® AI Security Exposure Management employs an AI skill to map these guardrails that are enabled in AI security platforms with the AI validation findings (automated red teaming results) that are reported
    by those platforms. This information about available guardrails can be used by vulnerability analysts to defer AI validation findings that are mitigated by these guardrails.

MITRE ATLAS techniques

:   AI security platforms associate all the findings, that is, vulnerabilities, validation findings, and posture findings, with relevant MITRE ATLAS tactics and techniques. This information is imported by your ServiceNow AI Platform® instance and displayed as part of the AI security finding details.

## AI Security Exposure Management users {#exploring-ai-security-exposure__cf-exploring-parent-users}

As an example, consider a vulnerability analyst and a vulnerability team that works for a large financial
services company. The team is in the process of converting legacy applications into AI-native applications and is encountering a high volume of AI exposures. To help them mitigate high risk exposure threats and identify and defer AI
security issues that have guardrails already in place for their large volume of exposures, this vulnerability team requires an automated remediation workflow.
{#exploring-ai-security-exposure__table_omj_wry_q3c__entry__2}

| User | Description |
|-|-|
| Vulnerability analysts, vulnerability managers, and Chief Information Security Officers (CISOs) | Monitor the organization's overall risk posture across integrated environments, ensuring accurate asset discovery and classification for AI exposures correlation. These roles serve as an escalation point for remediation teams. They assign remediation tasks based on asset ownership and severity, and organize AI exposure information into dynamic remediation tasks to streamline prioritization. Additionally, these roles deliver actionable dashboards and reports to track remediation progress, highlight critical AI exposures, and communicate the current risk posture to stakeholders. |
[Table 1. Users]

{#exploring-ai-security-exposure__table_omj_wry_q3c}

## AI Security Exposure Management benefits {#exploring-ai-security-exposure__cf-exploring-parent-benefits}

{#exploring-ai-security-exposure__table_rmj_wry_q3c__entry__3}

| Benefit | Feature | Users |
|-|-|-|
| AI exposures is a dedicated module in the Security Exposure Management workspace that provides visibility into the entire AI attack surface. Data about vulnerabilities, validation or automated red teaming findings, and security posture findings or configuration issues in various AI assets is available. | AI Exposures module | Vulnerability analysts, vulnerability management teams, Chief Information Security Officers (CISOs). |
[ ]

{#exploring-ai-security-exposure__table_rmj_wry_q3c}

## What to explore next {#exploring-ai-security-exposure__cf-exploring-parent-links}

To learn more about configuring and using AI Security Exposure Management, see:

* [Install and configure AI Security Exposure Management](https://servicenow-prod.fluidtopics.net/GTk7cYyzziaPpnYQxHiJAg "Install and configure the required applications.")
* [Using the AI guardrails helper skill and agentic workflow](https://servicenow-prod.fluidtopics.net/FQmdvLEryKFp8nI8GejSPA "You have the option to use a generative AI skill and agentic workflow to help you understand what type of findings you have, understand the guardrails associated with findings, and see why the skill mapped guardrails to particular findings.")
* [Viewing AI Exposures](https://servicenow-prod.fluidtopics.net/P8GUyl9Gm5LN36RikAsmpg "Access the entire attack surface across various types of findings on the AI Security Exposure Management dashboard on the AI Exposures module. AI exposures as a dedicated module of the Security Exposure Management workspace.")
* [Configuring remediation task rules](https://servicenow-prod.fluidtopics.net/RmdlpBHNSZWENp1hmEfORQ#sem-configure-remediation-task-rules "By configuring remediation task rules, you can automatically group findings based on filter conditions.")
{#exploring-ai-security-exposure__ul_smj_wry_q3c}
* **[Using the AI guardrails helper skill and agentic workflow](https://servicenow-prod.fluidtopics.net/FQmdvLEryKFp8nI8GejSPA)**   
  You have the option to use a generative AI skill and agentic workflow to help you understand what type of findings you have, understand the guardrails associated with findings, and see why the skill mapped guardrails to particular findings.

*[\>]: and then


