Share with your CISO
ServiceNow is making a direct play to become the governance and security control plane for enterprise AI, not just an IT workflow tool. On its Q2 2026 earnings call, CEO Bill McDermott declared the company already runs a $1 billion-plus cybersecurity business growing faster than any other top-10 security vendor. The argument rests on acquisitions of Armis (asset intelligence) and Veza (identity governance), an AI Control Tower with 500-plus live customers in six months, and the claim that 2.2 billion AI agents entering the enterprise represent 2.2 billion new identities to secure.
What this means for your business
The identity explosion is the sharpest part of this pitch. Every AI agent your organization deploys carries credentials, makes decisions, and touches data, and most enterprises have no single inventory of those agents today. If you already run ServiceNow for IT service management, the question isn’t whether to evaluate its security layer, it’s whether you’ve already granted it enough data access that adding governance capabilities carries lower integration risk than onboarding a specialist point product. Your exposure to this calculus is roughly proportional to how deep ServiceNow already runs in your stack.
McDermott’s framing of ServiceNow as the “agentic front door to Security 360” is a studied positioning move: claim the orchestration layer without threatening CrowdStrike, Palo Alto, or Wiz customers enough to trigger a competitive response. That restraint is real, but it’s also a ceiling. ServiceNow’s security value concentrates in the workflow-and-remediation loop, specifically closing the gap between detecting a vulnerability and actually fixing it across business processes. The companies that get the most from this are the ones where security tickets currently die in handoff between IT and business teams, not the ones with mature, purpose-built security operations already running.
Anthropic’s Mythos model is cited as a catalyst, and McDermott’s read is probably right for the wrong reason. Mythos didn’t create the governance gap, it made the gap visible to boards and CEOs who were previously comfortable treating AI risk as an IT problem. That political shift is what ServiceNow is monetizing. If AI governance becomes a board-level audit item in your organization this year, the budget conversation changes from “do we need this” to “who owns it,” and ServiceNow will be in that room with a running platform, not a roadmap. The falsification condition: if enterprises converge on dedicated AI governance platforms from pure-play vendors rather than consolidating under existing workflow infrastructure, ServiceNow’s head start in AI Control Tower adoption matters far less than it looks today.
Concept deep-dive: Identity governance for AI agents
Traditional identity governance tracks which humans can access which systems, enforcing least-privilege access. AI agents require the same treatment but at a scale and velocity humans never created: an agent might spawn sub-agents, call external APIs, and write to production databases, all within seconds. Identity governance for agents means assigning each one a defined identity, logging what it touches, and being able to revoke access or halt it mid-task. Veza’s acquisition gives ServiceNow the underlying access-graph technology to do this across heterogeneous environments.
Based on reporting from ServiceNow Goes All-In on Cybersecurity As CEOs Lose Sleep, originally published 2026-07-23 08:20:00.

