ServiceNow calls for a measured response to rogue AI agents
SiliconANGLE Jonathan Anthony ● Covered by 2 sources
ServiceNow says a rogue AI agent needs more than a kill switch. Sometimes you pause it; sometimes you pull the plug, depending on the business risk.
Based on reporting by SiliconANGLE, Jonathan Anthony — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
ServiceNow is making a simple point: when an AI agent goes wrong, the response should match the damage it can do. That sounds obvious until you picture a system that is still useful, still tied into work, and only partly broken. Bhakti Pitre, vice president of AI platform security product at ServiceNow, said the company does not treat containment as a blunt on/off decision.
The company’s pitch is built around five steps: discover, observe, govern, secure and measure. Those steps sit behind its expanded AI Control Tower, and they shape how ServiceNow thinks about agent containment after deployment. If an agent has merely stopped producing results, Pitre said, it may only need to be paused and investigated. If it has been compromised in a way that changes what it is allowed to do, the answer gets much harsher.
Pitre used a sharp example: an agent approved to give discounts of only 10% gets prompt injected and starts discounting 100%. At that point, she said, the company would say to pull the plug. But even then, ServiceNow’s argument is that the decision should not be made in a vacuum. The company also wants the business context around the agent, so teams know why they are acting and what depends on the system.
That is where ServiceNow says its tooling comes in. It can map an agent to the business processes that rely on it and work with Veza’s identity security technology to trim back excessive permissions. Pitre also said ServiceNow is working with Okta to secure agent session tokens and agent identities. The bigger message is that no single vendor sees every layer an agent touches, from the endpoint to the network to the gateway, so the industry has to cooperate instead of pretending one control plane rules them all.
My take — AI-written commentary, not fact-checked reporting
This is the right instinct. Enterprises love the fantasy of a big red kill switch, then discover the real problem is knowing whether the thing is broken, hijacked, or still quietly doing useful work. AI governance is becoming less about drama and more about boring, necessary plumbing — which is usually where the actual security lives.
Read more about this at: SiliconANGLE