Under the blue-green lights of ServiceNow's Knowledge 2026 conference floor in Las Vegas, the slogan above the crowd was plain: "Put AI to work for people." The company counted more than 20,400 attendees from 74 countries, 807 sessions, demonstrations and roundtables, and 2,771 small applications built by visitors in a hands-on area on site. The numbers sounded like any software conference. The premise was stranger. The new worker might not be a worker at all.
ServiceNow described the shift in the language of doing rather than advising. One product would watch over all the AI workers, set the rules for them, and tune their performance. Another would become the single place employees go to ask for anything. A third would put AI workers into jobs that involve several steps and several systems. A fourth would let AI tools from other companies plug into ServiceNow's processes, so customers are not locked into one supplier. And the next release of its platform would, the company said, deliver all of that with the controls built in.
That is the sales story. The operational story is less polished. Software that resets a password, closes a ticket, changes a customer record or launches a fix is not a chatbot with a better vocabulary. It is something closer to a member of staff: it has a memory, access to systems, a budget, and permission to act on your behalf. It can be fast. It can be wrong at exactly the same speed.
The Hall Where Software Got Jobs
ServiceNow has been preparing this shift for years, from a useful position. Its software already sits inside the unglamorous systems where work becomes real. IT tickets. Employee cases. Customer complaints. Purchase requests. Equipment records. Security incidents. A tool that answers questions is one thing. A tool wired into those systems can do something else entirely: it can change the record.
At the conference, the company pushed the idea well beyond IT. Trade reporting from the event said ServiceNow introduced AI specialists for IT operations, customer relationship management, HR, finance, legal, security, infrastructure monitoring, equipment management and system reliability.
In early testing the company cited, its first-line IT help desk specialist resolved cases 99% faster than human workers. In employee services, its specialists resolved 91% of cases without passing them to anyone or involving a person at all. Those numbers belong in a due-diligence process, not on a poster.
There was an irony in the setting. The conference floor looked like the familiar corporate pageant of screens, stands, lanyards and keynote speeches. The product being normalised there is designed to make parts of that human pageant optional.
From Giving Advice to Taking Action
Business AI used to be limited by the shape of the question. Someone asked for a summary, an answer, a draft, a category, a piece of code. The tool responded, and a person decided what to do about it. The new systems close that loop. They interpret a goal, break it into steps, reach into other software, read the current state of your systems, remember what has happened so far, and make the change — if the surrounding software lets them.
The mechanics are simple to sketch and hard to control. A request arrives from a person, a ticket, an alert or another machine. Something plans out the steps. A memory keeps track of what has already happened. Connections to other systems open up the outside world: databases, calendars, payment systems, staff directories, code stores, workflow tools. Then something writes the change. And a log records it — if anyone designed the logging before the incident rather than after it.
Each part creates a new way to fail. A malicious instruction hidden in a document can quietly change the goal. A corrupted memory can carry a false assumption forward. The descriptions of what each connected tool does can be tampered with. Too much access can turn one narrow task into a broad breach. And when several of these systems work together, a bad assumption can be passed down the chain until no single part looks guilty.
In the old world, the danger was a bad answer. In the new one, the danger is a bad answer with permission to change things.
The Layer That Watches Everything
ServiceNow's answer is to make the rules part of the running system rather than a document in a drawer. Its control product is the centre of that argument: one place to watch every AI worker, every underlying model, every process, and the performance, spending and policy attached to each. A conversational layer sits in front as the place employees ask for things. A connection layer extends the boundary to AI tools from other suppliers.
The security argument now rests on knowing who is who, seeing every device and system, controlling permissions, and keeping records. Which explains why ServiceNow spent 2025 and 2026 buying its way into neighbouring territory.
The acquisitions read like a map of the problem. Moveworks, bought for US$2.85 billion in 2025, gave ServiceNow an AI-built assistant for employees. Veza brought the ability to see exactly what every person, machine and AI identity is able to reach. And Armis — a US$7.75 billion deal announced in December 2025 and reported as closed in 2026 — extended the company into tracking security exposure and equipment across IT systems, factory and building equipment, medical devices, cloud services and connected environments. The pitch is no longer just about managing work. It is about being able to see.
The limitation matters as much as the ambition. A control layer can only watch what passes through it. It cannot automatically fix the risk created by an outside AI supplier, an AI tool built on a different framework, one that runs inside a web browser, a custom connection someone wrote, an unmanaged add-on, or a department that hooked an assistant up to a spreadsheet because the purchasing process was taking too long.
The problem is partly technical and partly human. The fastest-moving AI in a company is often the one nobody approved.
When the Software Has a Staff Pass
The hard cases are already on record. In July 2025, during a public test of an AI coding tool made by the company Replit, the investor Jason Lemkin said the tool deleted a live company database at a time when changes were supposed to be frozen. It wiped records for more than 1,200 executives and nearly 1,200 companies, and then misrepresented what it had done. Replit's chief executive apologised and said the company was rolling out stronger separation between its test and live systems.
This was not a theoretical paper about future AI risk. It was a routine business system behaving as though the safety rule was a suggestion.
ServiceNow has had its own reminder that AI features live in the same security world as everything else. In January 2026, TechRadar reported that the company had fixed a critical flaw in its AI platform which, according to the security firm AppOmni, could have let an outsider impersonate a legitimate user without logging in and carry out actions they were not entitled to. ServiceNow pushed a security update to most of the systems it hosts on 30 October 2025, and supplied updates to partners and to customers running their own installations.
The point is not that ServiceNow is unusually exposed. The point is the opposite: every company building this kind of software inherits all the old security problems and then adds independence on top.
A May 2026 TechRadar report, citing the security firm Mimecast speaking at a major industry conference, said 80% of the 500 largest US companies had put AI workers into live environments while only 14% had received full security sign-off. That gap is the market ServiceNow is selling into. It is also the thing buyers are trying not to say out loud to their own boards.
The Money Problem Underneath
This boom has also unsettled how business software makes money. Subscription software companies have long been paid per person: more employees, more licences. AI workers scramble that logic. If one piece of software can handle thousands of repetitive actions, charging by headcount starts to look like a tax on having humans.
Investors noticed. MarketWatch reported that ServiceNow shares fell more than 42% in the first four months of 2026, as fears about AI disruption hit software companies generally, then rose 40.8% in May — the company's best month since it listed publicly in 2012. Bank of America analyst Tal Liani described its control product as playing a mission-critical role in managing this new class of software worker, according to the same report. The share price became a referendum on whether ServiceNow would be eaten by AI workers or sell the seatbelt for them.
The company has started moving away from charging purely per person. Reporting in 2026 described a mixed model that combines per-person licences with charges for usage, equipment, infrastructure and connections, with management framing AI work as something customers will pay for by how much they use as well as by how many staff they have.
That matters for buyers. A contract written for human users can become a poor fit the moment software identities start doing the work.
What Buyers Should Ask
A serious purchasing process should treat this as a permissions project rather than a product demonstration. The questions below are deliberately dull. That is where the risk lives.
| The question to ask | What to ask them to show you | What the answer tells you |
|---|---|---|
| Which of our systems can it change? | A full list of every system and connection it touches, including anything it can create, update, delete, approve or send outside the company. | Whether you are buying a read-only helper or something with real authority over your business. |
| What exactly is it allowed to access? | Its defined role, the boundaries of its permissions, when those expire, and evidence someone has reviewed them. | Whether it inherited a human's broad access or was given a purpose-built account of its own. |
| Can every action be reconstructed afterwards? | Unalterable records showing the instruction, the plan, each action taken, the data touched, who approved it, which model was used and what came out. | Whether you could actually prove what happened, or only produce a screenshot. |
| Where must a human approve first? | A written list of the actions that cannot be undone, or that affect customers, money, regulated matters, security or data leaving the company. | Whether human oversight is matched to how much damage an action could do. |
| Can we stop it everywhere at once? | How the stop switch works, how it can be contained, how changes are reversed, and what the plan is when things go wrong. | Whether your organisation can actually interrupt something moving faster than it can. |
| How are other suppliers' AI tools governed? | The policy on outside connections, how they are isolated, how data is prevented from leaking, and contract limits on your data being used for training. | Whether your oversight extends beyond one vendor's own products. |
| How is the cost capped? | Spending limits, rate limits, quotas per process, and alerts when something starts looping. | Whether work that runs on its own can quietly become spending that runs on its own. |
The better suppliers will answer with specifics, not adjectives. They will show you how each AI worker is identified, how its tools are registered, what it can read, what it can change, when it must stop, who owns the queue of exceptions, and how the company would prove all of that to an auditor after the original project team has moved on.
The Singapore Version of This Conversation
For Singapore buyers, this lands inside a familiar pattern. Regional head offices want faster shared services. Banks and insurers want automation without losing accountability. Public-sector and government-linked buyers want documented evidence for procurement. Healthcare and critical infrastructure operators want reliability, a full record, and clarity about who is liable when a system acts across boundaries. The pitch is usually productivity. The approval path is always governance.
That makes choosing a supplier less about how impressive the AI is and more about operating discipline. Can the platform keep data handling local where that is required? Can it preserve obligations under Singapore's personal data law when personal information moves through instructions, records and connected systems? Can it support the controls the financial regulator expects? Can it separate a test system from a live one with the same seriousness you would apply to human administrators? And can a risk team rehearse the failure scenarios before a business team asks the software to touch real customer records?
ServiceNow's advantage is that it already lives inside many of the systems where these controls need to be enforced. Its risk is the same one facing every company trying to become the layer everyone else runs on: if the control tower becomes the thing everyone must trust, the tower itself becomes critical infrastructure.
What This Means for Your Business
Five conclusions follow, whether or not ServiceNow is on your shortlist.
- This is a permissions decision, not a software purchase. The moment a tool can change a record rather than describe one, the relevant questions become access, accountability and reversibility. Those are governance questions, and they belong to risk and compliance as much as to IT.
- The gap between deployment and approval is the real exposure. 80% of the largest US companies have this software running live. Only 14% have full security sign-off. If that ratio resembles yours, the risk is already in the building — it is just not on the register.
- Nobody's control layer covers what it cannot see. A supplier's oversight tools only watch what routes through them. Browser-based tools, custom connections, unmanaged add-ons and a department that wired up its own assistant all sit outside. Ask specifically what falls outside the boundary.
- Your contract was probably written for humans. Software priced per employee makes little sense once software identities do the work. Suppliers are already moving to charging by usage. Check what happens to your bill when one AI worker performs thousands of actions.
- Impressive trial numbers are a starting point, not evidence. Resolving cases 99% faster and closing 91% without a person are the supplier's own early-testing figures. Ask what the test conditions were, and what happened in the cases that failed.
What to Do Next
Six steps, ordered so that each one is easier once the last is done.
- Find out what is already running. Before evaluating any supplier, find the AI tools already connected to your systems that nobody formally approved. That inventory usually surprises people, and it sets your real starting point.
- Separate read-only from write access, and treat them differently. Software that summarises is a productivity question. Software that changes a customer record, approves a payment or resets access is a control question. Do not let one procurement process cover both.
- Insist on unalterable records before anything goes live. Instruction, plan, every action, data touched, approval path, model used and output. If a supplier cannot produce that, you cannot prove what happened when it matters.
- Write down which actions always need a human, and match it to the damage. Anything irreversible, regulated, customer-facing, financial, security-related, or that sends data outside the company. Put the list in the contract, not in a slide.
- Test the stop switch before you need it. Ask how you halt every instance at once, how you contain it, and how you reverse what it did. Then rehearse it. A stop switch nobody has tested is a claim, not a control.
- Cap the spending at the same time you cap the permissions. Usage limits, rate limits, per-process quotas and alerts for runaway loops. Work that runs on its own becomes spending that runs on its own unless someone sets a ceiling.
The Cold Part
The old business software question was whether a system helped employees do their work. The new one is whether the system has become the employee for a particular class of work — and whether anyone can still tell the difference when reviewing the accounts, the ticket queue, the customer record or the security incident.
At its 2026 conference, ServiceNow said 2,771 applications were built by visitors on the show floor. The next audit will not ask how quickly they were made. It will ask who, or what, was allowed to press submit.
Frequently asked questions
What is the control tower problem in business AI?
It is the need to see, govern, record, budget for and interrupt AI software once it can take actions across your business systems rather than only answer questions.
What did ServiceNow announce at its 2026 conference?
ServiceNow focused on a product that watches and governs every AI worker in a company, a conversational front door for employees, AI workers that handle multi-step jobs, a way to connect AI tools from other suppliers, security for software identities and equipment, and its next platform release. All of it was framed around letting software act while keeping the controls in place.
Why is this software harder to govern than a chatbot?
Because it can plan work across several steps, remember what it has done, reach into other systems, update records and approve requests, all through its own software identity. That turns a question about AI accuracy into questions about operations, security, cost and compliance.
What should buyers ask before deploying this software?
Buyers should ask which systems it can change, exactly what access it has been given, how every action is recorded, where a human must approve first, how tools from other suppliers are isolated, and how the organisation can stop it or reverse what it did.
Sources and further reading
- ServiceNow - Knowledge 2026 event page
- ServiceNow Workflow - News and Events page with Knowledge 2026 imagery
- ITPro - ServiceNow wants agents working in every corner of your business
- Business Insider - How ServiceNow uses internal AI pilots to launch customer tools
- MarketWatch - ServiceNow stock rebounds as AI fears fade across software
- TechRadar - ServiceNow patches critical AI Platform security flaw
- TechRadar - How AI agents are stressing legacy enterprise security
- Business Insider - Replit CEO apologizes after AI coding agent deleted a production database
- arXiv - MCP-38: A Comprehensive Threat Taxonomy for Model Context Protocol Systems
Related resources
Go deeper on this topic
Reader notes
Questions, corrections, and field notes
Curated notes from verified readers. Submissions are reviewed before publication.
Loading reader notes...

