Enterprises grapple with AI agents and shadow AI: identity risk
19 days ago • ai-security
ServiceNow announced on 2025-12-23 that it will acquire Armis to expand cyber exposure and security across IT, OT and medical devices, positioning the deal as a response to rising agentic-AI risks (ServiceNow release; TechTarget; The Register). Industry coverage frames the acquisition as a move to add specialized agentic-AI and device visibility to enterprise security stacks.
Executives and analysts say identity security and open technology choices will determine winners as AI agents enter workflows. DigiTimes reports 80% of global enterprises are experiencing AI agent failures amid governance gaps and highlights rising “shadow AI” — unsanctioned use of AI tools — which raises the risk of vulnerable AI-generated code and intellectual property (IP) exposure (DigiTimes; TechObserver). TechTarget and TechObserver also flag agentic-AI security as a primary target for acquisitions and integration.
Immediate actions for IT and security teams are clear: inventory agent usage, enforce identity and least-privilege access, add code review and runtime validation for AI outputs, and fold AI-agent risk into procurement and incident response processes. The ServiceNow–Armis tie-up — reported at about $7.7B by The Register — signals vendor consolidation and growing demand for integrated agentic-AI security controls.
Why It Matters
- Inventory shadow AI and agent deployments now — unidentified agents are a fast path to data and IP leakage.
- Enforce identity-based controls and strict least-privilege access for agents to limit lateral movement if credentials are compromised.
- Add automated code review and runtime validation for AI-generated outputs to catch vulnerable or IP-leaking code before deployment.
- Treat AI-agent risk as a procurement and incident-response requirement; require vendor SLAs, telemetry, and proof of integrated agent security controls.
Trust & Verification
Source List (5)
Sources
- ServiceNow (Investor Relations)OfficialDec 23, 2025
- TechTarget (Search Customer Experience)Tier-1Dec 21, 2025
- The RegisterTier-1Dec 23, 2025
- Tech Observer MagazineOtherDec 24, 2025
- DigiTimesOther