← Back to list

Your risk committee is your AI accelerator

THE SERVICENOW AI FIELD GUIDE — POST 5 OF 8

Mark Orsborn · 2026-07-10 11:56 · 0 claps · 2.5 min read
#ai #ai-governance #ai-risk #servicenow
Open on Medium ↗
Wiki topics: AI · AI · General STP · Startups & Venture

Your risk committee is your AI accelerator

THE SERVICENOW AI FIELD GUIDE — POST 5 OF 8

The governance layer that lets you trust an AI agent with real work is no longer something to buy or build. As of July, it ships with every ServiceNow licence, so the advantage now goes to whoever switches it on first.

Start with the fact that changes how you sequence everything else. ServiceNow’s AI Control Tower is now bundled into every licence tier, Foundation included, under July’s new commercial model. Until now, it was a separate purchase, which is precisely why so many organisations deployed AI first and reached for the controls afterwards. That order is now inverted: the governance work most teams were planning to postpone is already on the shelf, waiting to be switched on.

What that capability looks like in practice was on show at Knowledge 2026, where ServiceNow had the control tower catch a pricing agent hijacked by a prompt injection hidden in an order payload, told to ignore the pricing rules and keep the change out of its own logs. The tower flagged the behaviour in real time, mapped the blast radius through Veza’s access graph, and shut the agent off with a single control. It was a demonstration, as product capabilities are, but the capability is real and reaches general availability in August.

What switching it on gives you

It spans five functions: discover the AI running in your estate, including agents built outside ServiceNow; govern what each is permitted to do; secure them against manipulation; observe their behaviour; and measure cost and value, including a tracking layer for the consumption spend this new commercial model runs on. Integrations with Microsoft’s agent ecosystem and NVIDIA extend the reach beyond the platform’s own walls. Read alongside the acquisitions, Armis holding the map of every asset, Veza the permissions of every identity including the non-human ones, Traceloop the record of how the models actually behave, the direction is clear: the platform now gives agents authority and the means to govern that authority in the same place.

Governance is now an accelerator, so use it as one

The reframe is the actionable part, and in my experience it is the one leaders most often miss. A control tower turns governance from the thing that slows AI down into the thing that lets you move faster with confidence, because the constraint on scaling agents was never really the technology; it was your risk committee’s willingness to sign. Give them visibility and control and the yes comes quicker. Start by switching on discovery and pointing it at your own estate, including the unofficial agents teams have already adopted; an honest inventory is the foundation everything else builds on, and an amnesty surfaces it faster than an audit. Then, for the first workflow you intend to make agentic, write the permission boundary before you deploy: what the agent may decide on its own, what it must escalate, expressed as policy a risk function can read. And make behavioural review routine, so someone actually reads what the agents did last week, the way an engineer reads the error log. None of this is heavy, and all of it now runs on tooling included in the new licences.

Start Now

Open an AI register this week, even in a spreadsheet: agent, purpose, owner, permissions, data touched. Populate it by amnesty, not audit.

Then take your single most autonomous workflow and write its boundary in two sentences: decides alone / must escalate. If you cannot, neither can the agent.

We build AI governance frameworks that satisfy risk committees without strangling delivery, from operating model to Control Tower implementation, because approval speed is now a competitive metric.


메타데이터
post_id
d73618edefcd
slug
your-risk-committee-is-your-ai-accelerator-d73618edefcd
url
https://medium.com/@markorsborn/your-risk-committee-is-your-ai-accelerator-d73618edefcd
canonical_url
https://medium.com/@markorsborn/your-risk-committee-is-your-ai-accelerator-d73618edefcd
author_url
https://medium.com/@markorsborn
status
ok
fetched_at
2026-07-13 06:23:13