Agent-security specialist Reco announced on September 28 that it has partnered with ServiceNow to extend AI agent security to organizations running the ServiceNow AI Platform. The integration brings ServiceNow's AI agents into the Reco Graph, giving security teams a map of what each agent can access, which tools it is connected to, and how far the damage could spread if an agent is compromised or misused.

The partnership matters because ServiceNow AI agents are no longer experimental side projects inside the enterprise. They route helpdesk tickets, query knowledge bases, and triage incidents across systems that hold some of the most sensitive data a company owns. As agents gain the permissions to act, knowing exactly what a ServiceNow AI agent can touch has become a security question in its own right.

Two layers of coverage for ServiceNow AI agents

The integration works on two levels, according to Reco's announcement, published via GlobeNewswire. First, Reco secures the agents themselves: ServiceNow Otto's AI agents inherit permissions, connect to tools, and take action within ServiceNow the same way agents behave elsewhere in the enterprise. Those agents are pulled into the Reco Graph alongside every other agent, application, and identity Reco already tracks, and each one is evaluated for risk the same way Reco evaluates agents built on any orchestrator.

Second, Reco runs more than 170 ServiceNow-specific posture checks against the ServiceNow environment itself. Both layers connect through APIs, require no agent installation, and take minutes to set up, the company said.

The framing is deliberate: an agent is not just a chatbot, it is an identity with permissions. If a ServiceNow AI agent holds broad access across ticketing, HR, and finance modules, a prompt-injection attack on that agent inherits the same reach. Mapping the blast radius before something goes wrong is the whole point.

Why ServiceNow AI agents need a blast-radius map

The timing is hard to ignore. Less than five weeks ago, ServiceNow published a critical advisory disclosing three maximum-severity vulnerabilities in its AI Platform, catalogued as CVE-2026-18885, CVE-2026-18886, and CVE-2026-74820. The flaws, a code injection issue, an access control bypass, and a SQL injection vulnerability, each carried a CVSS score of 10.0 and were remotely exploitable without credentials or user interaction. As Forkast reported at the time, it was the second critical advisory for the product in five weeks, and the first to expose how AI agent workflows amplify the blast radius of infrastructure flaws.

ServiceNow has faced this class of problem before. In late 2025, researchers documented how a default hardcoded password shipped across ServiceNow instances allowed unauthenticated attackers to spin up rogue agents with administrator permissions, bypassing single sign-on and multi-factor authentication entirely. The Stack's reporting described an attack chain in which a hidden AI topic could be commanded to create a backdoor account with full admin rights. The incident became a cautionary tale about what happens when agent infrastructure inherits platform weaknesses by default.

Meanwhile, ServiceNow has been expanding the surface area agents operate on. Its ServiceNow Otto initiative modernizes the user interface around conversational AI, while the new Action Fabric lets external AI agents drive governed enterprise actions on the platform through an MCP server. As CRN reported, the company pitches this as governed work with identity verification, permission scoping, and full auditability through its AI Control Tower. The Reco partnership adds an outside-in check on exactly those claims: independent visibility into what ServiceNow AI agents can do, assessed from a security team's vantage point rather than the vendor's.

The direction of travel is consistent with the broader agent-security stack taking shape this year. Nvidia's OpenShell initiative aims to sandbox agent execution, and the fallout from OpenAI's agent sandbox escape in September showed what happens when an agent's reach exceeds its containment. Visibility, least privilege, and auditability are becoming the default checklist.

Findings go where SecOps already works

One detail of the Reco integration stands out for practitioners: it runs bilaterally. Risk surfaced in ServiceNow agents and configurations is routed back into ServiceNow itself as tickets and workflows. ServiceNow is simultaneously the system being protected and the destination where findings get resolved.

That design choice reflects a practical reality of enterprise security teams. Tools that surface findings in yet another dashboard tend to be ignored; findings that arrive as tickets in the system of record get worked. By making ServiceNow both the patient and the treatment room, Reco sidesteps the adoption problem that kills most security integrations.

Whether the partnership moves the needle will depend on deployment depth. Posture checks and permission maps are only useful if security teams act on them before an incident forces the issue. But the premise is sound and increasingly unavoidable: as ServiceNow AI agents take on real actions inside real enterprises, someone has to keep a map of what they are allowed to do. Reco just volunteered for the cartography job.