Three quarters of CIOs can't see their own AI tools

Three quarters of the CIOs in diginomica's own CIO network survey said they cannot fully see every AI tool running in their systems. 23% said AI governance is lagging behind deployment. Another 12% said they are deploying faster than they can govern, and 12% have no AI governance in place yet. Derek du Preez published those numbers on September 18 alongside ServiceNow's security pitch, and the numbers are the harder half of the story.

If you run security or platform work inside a ServiceNow shop, the uncomfortable part is that you probably cannot prove your own organisation sits in the visible quarter. Someone in finance is running a browser extension against a customer spreadsheet. A developer wired an API key into a build step last quarter. A team expensed seats on a corporate card and never opened a ticket. None of that was malicious, and none of it lands in an asset record.

That gap is what ServiceNow is selling into, and the answer it has built is the same consolidation play that built the workflow business.

What shift zero is actually asking for

Yevgeny Dibrov, SVP and GM of cybersecurity and risk at ServiceNow and formerly a co-founder of Armis, calls it shift zero. "Shift zero means shifting all the way to the left," he says, and the operational demand underneath that is detection speed. "You must be able to detect in real time" is how he frames the requirement, and he uses the phrase "in real time" twice in a single sentence, which tells you what the product is being sold on.

The reasoning is an exposure window. "You don't have time, because if you are exposed even for a very small period," he says, and his point is that attackers already know the attack paths through your organisation and will move on any opening. On the threat side he describes an ordinary attacker now executing at the level of a nation-state operator. diginomica reports that framing without an incident count behind it, and our read is that it describes a speed problem rather than a volume problem.

The consolidation argument has money behind it

ServiceNow acquired Armis for nearly $8 billion in late 2025 and also picked up identity security vendor Veza. The company reported its AI business passing $1 billion in July. That is a lot of capital pointed at one claim, which is that detection belongs next to the workflow that fixes whatever got detected.

The claim stands up on its own merits. A vulnerability finding turns into a change request with an owner attached before anything actually gets fixed, and if the finding lives in a separate console, a human copies it across and the clock restarts. We have argued a version of this before about policy enforced at the tool call instead of in a side system, and about MCP actions that run on the roles your instance already has. Putting detection on the platform that already holds the remediation record removes a handoff that fails quietly.

It all rests on the asset data underneath

Real-time detection across an estate is a claim about coverage, and coverage is a claim about your CMDB. A correlation engine reading a CI with a stale owner or a missing relationship will return a confident answer about a service that no longer looks that way. The detection was real time. The picture it got matched against was eight months old.

We have covered what a ServiceNow CMDB needs before an agent reads it and the CMDB that two teams claim and nobody owns, and both point the same direction. Identification rules and reconciliation decide what any detection layer can see. Consolidating onto one platform does not repair either of them. It makes the same data authoritative for more decisions and faster decisions, which is an improvement when the data is good and a wider blast radius when it is not. We landed somewhere similar on ServiceNow's autonomous security specialists earlier this month.

What to verify before you buy a platform answer

Pick one revenue-facing service and do the arithmetic yourself. Count what your CMDB says belongs to it, then count what your last discovery run actually found. Write the difference down as a number, because that difference is the ceiling on anything a detection platform can tell you about that service, no matter how fast it runs.

Then do the AI tool version of the same exercise. Pull every AI-related line item out of expense and procurement data for the last two quarters, and check how many of those tools any system you already own can currently see. Our guess is that the answer embarrasses somebody, which is a good reason to run it yourself before a vendor runs it for you inside a demo.

Ask the mechanism question as well. Real time is a latency claim, so ask what the detection latency actually is for a brand new asset appearing on the network, and whether that comes from a scheduled discovery job or from passive observation of traffic. The diginomica piece does not say, and that is the part we would ask about on the first call.

The question to take into your next security review

Ask whoever owns your CMDB for one number: the percentage of assets they would personally defend in an audit tomorrow. Ask for the figure they will stand behind in a room, rather than the completeness score sitting on a dashboard.

Whatever comes back is the number shift zero performs against. If it is 70%, a real-time detection platform gives you real-time answers about 70% of your estate, and the attacker Dibrov describes is already working the rest of it. Size that gap before you sign anything that depends on it being small.