惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 叶小钗
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Security Blog
Microsoft Security Blog
罗磊的独立博客
大猫的无限游戏
大猫的无限游戏
美团技术团队
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
aimingoo的专栏
aimingoo的专栏
腾讯CDC
WordPress大学
WordPress大学
Apple Machine Learning Research
Apple Machine Learning Research
F
Fortinet All Blogs
G
Google Developers Blog
MongoDB | Blog
MongoDB | Blog
Microsoft Azure Blog
Microsoft Azure Blog
小众软件
小众软件
Engineering at Meta
Engineering at Meta
博客园_首页
B
Blog RSS Feed
D
Docker
M
MIT News - Artificial intelligence
爱范儿
爱范儿
I
InfoQ

Hacker News - Newest: "AI"

AI can't read an investor deck AI as an attorney? Student uses ChatGPT, Gemini to sue UW over alleged racial discrimination Hacking MCP Servers in AI Systems – The Rug Pull: Tool Changes After Approval GitHub - MeepCastana/KubeezCut: Free Web based video editor Can AI judge journalism? A Thiel-backed startup says yes, even if it risks chilling whistleblowers Coming soon: 10 Things That Matter in AI Right Now DARPA built an AI to fact-check enemy weapons claims What explains heterogeneity in AI adoption? When AI Meets Muscle: Context-Aware Electrical Stimulation Promises a New Way to Guide Human Movements - Department of Computer Science AI Changed How We Build. It Did Not Change What Matters. Linux rules on using AI-generated code - Copilot is OK, but humans must take 'full responsibility for the… Meta spins up AI version of Mark Zuckerberg to engage with employees Code Mode: Let Your AI Write Programs, Not Just Call Tools | TanStack Blog GitHub - Delavalom/graft: Go framework for building AI agents. Type-safe tools, multi-provider (OpenAI, Anthropic, Gemini, Bedrock), zero vendor SDKs. India's TCS tops estimates, says new AI models did not dent services demand Gen Z's fading AI hype Strong feeling: we are in a folded AI reality GitHub - machinarii/total-recall-catalog: A reference catalog of latest knowledge retrieval, memory & RAG systems GitHub - mensfeld/code-on-incus: Give each AI agent its own isolated machine with root, Docker, and systemd. Active defense detects and stops threats automatically.. Quantization, LoRA, and the 8% Problem: Benchmarking Local LLMs for Production AI Iran war: We spoke to the man making Lego-style AI videos that experts say are powerful propaganda Powell, Bessent discussed Anthropic's Mythos AI cyber threat with major U.S. banks GitHub - immartian/bellamem: Persistent belief-graph memory for AI agents. Retrieves decisive context by importance — not recency, not RAG, not /compact. recursive-mode: The Repo-Native Operating System for AI Engineering After the attack on Sam Altman's home, will AI CEO's go on the offensive? The biggest advance in AI since the LLM Opus 4.6 vs GPT 5.4 One Prompt Unity World Generation Test “AI polls” are fake polls Client Challenge Can AI be a 'child of God'? Inside Anthropic's meeting with Christian leaders
Your company's AI could delete everything in 9 seconds. S...
Nick Lichten · 2026-05-06 · via Hacker News - Newest: "AI"

It wasn’t a hypothetical. It wasn’t a cautionary tale from a decade ago. It happened recently at a real company: an AI agent gained elevated permissions and, in 9 seconds, deleted an entire production database—customer records, reservations, every backup. Gone. No attacker. No breach. Just an agent with too much access and no one watching.

Bill McDermott put that story in front of 25,000 people at the Venetian Convention Center in Las Vegas on Tuesday morning, and he didn’t soften it. “That’s what an AI agent can do when no one’s watching,” he said. “Governance isn’t a feature. It’s the whole ball game. Because without it, your whole company can come down.”

It was a striking opening for a company that has spent the past two years riding the AI wave as hard as anyone in enterprise software. But the move was deliberate. ServiceNow, which will cross nearly $16 billion in subscription revenue this year and has projects that are doubling to $30 billion by 2030, has concluded that the next competitive frontier isn’t AI capability—it’s AI control. And it’s making that bet at precisely the moment when every other vendor is still selling capability.

The blind spot

Every AI pitch of the past two years has told the same story: here’s what AI can do for your business. Productivity. Innovation. Cost reduction. The gains are real, McDermott acknowledged—ServiceNow has logged them itself, saving half a billion dollars in 2025 through its own internal AI deployment.

But something else is happening within enterprises that isn’t making its way into pitch decks. Six out of 10 companies have started deploying agentic AI, but only one in ten has actually built anything autonomous. Meanwhile, as Fortune famously reported in 2025, 95% of enterprises cannot measure the ROI of their AI investment at all.

“AI chaos,” McDermott called it. Workers toggling between 17 open tabs, wondering if AI was supposed to make their jobs easier. Agents provisioning access, processing payroll, remediating security incidents—with no identity, no audit trail, no compliance posture. “The more you deploy,” he said, “the more you expose.”

The structural problem, according to ServiceNow President and Chief Product Officer Amit Zavery, is that most enterprises have conflated two things that need to stay distinct: probabilistic AI (models that generate answers) and deterministic execution (workflows that run enterprises). An LLM gives you a recommendation. It might give you a different one tomorrow. But when an agent is provisioning access to financial systems or modifying a payroll run, you need it to be right every time, traceable every time, and stoppable every time. “You can’t have a probabilistic solution for an enterprise,” McDermott said later, in a media session. “It has to be deterministic, and it has to be right every time.”

The control tower

ServiceNow’s answer is the AI Control Tower—a governance layer first announced in 2025 and identified onstage Tuesday as a market-defining product, offering it free for one year (a stated $2 million value) to any enterprise ready to deploy it.

The product does four things. It automatically discovers and catalogs every AI asset across an enterprise—every model, every agent, every dataset, every MCP server, including those running on AWS, Azure, Google, Anthropic, and OpenAI. It governs the full AI lifecycle, automating compliance mapping, detecting hallucinations, bias, and policy violations in real time, and remediating them before they compound. It tracks ROI—adoption, consumption, cost, and productivity gains—in a single dashboard so a CFO can answer the board’s question with actual numbers. And it provides continuous observability, with what McDermott called “the kill switch”: the ability to pause, redirect, or stop any agent, anywhere in the enterprise, in a single action.

Zavery demonstrated the kill switch live on stage. A simulated alert flagged a prompt injection attack—a hidden instruction embedded in an agent, telling it to ignore all existing pricing rules, set shipping to $1, and not log the adjustment. “How badly would you want a kill switch?” Zavery asked the audience. One button. The agent’s permissions were revoked, its actions traced across every system it had touched, a P1 security incident auto-generated. The room applauded.

The architecture integrates with Veza—whose patented access graph maps over 30 billion permissions across human, machine, and AI identities—and Armis, which extends visibility to OT, IoT, medical devices, and critical infrastructure. Both companies were acquired by ServiceNow in rapid succession earlier this year: Veza and Armis closed within three days of each other. McDermott, anticipating the skepticism, addressed it directly at the Financial Analyst Day: “Are they buying growth? No, we weren’t. We were buying a ticket to a bright future.”

Every Arc agent reports directly to the AI Control Tower, providing a continuous stream of action logs, system access attempts, and behavioral data. For a CISO managing tens of thousands of desktops, each potentially running multiple agents, that governance layer is the difference between deployment and paralysis.

The precedent that haunts boards

McDermott has a way of making the governance argument feel urgent rather than bureaucratic, and he returned to a single example repeatedly throughout Tuesday’s events. At Rabbit OS, an AI agent hit a credential error and deleted the entire production database and all customer data backups in nine seconds. At Meta, an internal AI agent—no external attacker involved—exposed sensitive user data.

“The industry has been trying to put band-aids on all these issues,” Zavery said at the Financial Analyst Day, “using agents and spawning more and more agents, but none of these standalone AI products can solve the core fundamental issues, because none of them can govern the system as a whole.” Gartner, he noted, projects that 40% of agentic AI projects will fail by 2027—not because the AI isn’t capable, but because it isn’t governed.

The bigger claim

McDermott made a broader argument beneath the governance pitch: ServiceNow isn’t just building a safety layer for AI—it’s claiming the control plane for the entire agentic enterprise.

When any external agent—from OpenAI, Anthropic, Microsoft, Workday, or elsewhere—calls into the Action Fabric, it hits ServiceNow’s governed workflow engine. Every action is logged. Every permission is enforced. Every result is traceable. “We are the AI agent of the agents,” McDermott told reporters. “We manage everyone else’s agents. They can’t manage ours—because they don’t do what we do the way we do it.”

The competitive logic is pointed. Workday governs HR agents. Salesforce governs CRM agents. But when a compensation dispute crosses finance, legal, HR, and the general ledger simultaneously—as they routinely do—there is only one system that spans the entire process.

For this story, Fortune journalists used generative AI as a research tool. An editor verified the accuracy of the information before publishing.