Tenable Launches AI Aware to Address AI-Era Security Risks
Tenable, a longtime leader in exposure management, has introduced AI Aware—its new capability built to spot and understand the risks that come with artificial intelligence. The goal is straightforward: make it easier for security teams to see where AI shows up across the environment, pinpoint weaknesses tied to AI applications, frameworks, and tools, and act before issues turn into incidents. With clearer visibility, organizations can keep AI projects moving without losing control of risk.
AI Aware is designed for the way AI actually gets used today—often fast, often distributed, and sometimes without formal approval. It gathers the right signals, turns them into a usable picture, and helps teams prioritize what to fix so day-to-day operations don’t stall.
AI Adoption Is Surging—So Are Its Security Gaps
AI has moved from pilot to production at record speed. In that rush, basic guardrails are easy to miss. Teams experiment with new tools, connect services, and pull in packages that weren’t reviewed centrally. The result: cybersecurity programs are now contending with a new mix of problems—unapproved AI usage, data exposure paths that weren’t there before, and vulnerabilities buried in the tooling that supports AI development and deployment.
Security leaders must now answer practical questions: Which AI apps are running in our environment? Who turned them on? Which hosts rely on them? Are any of them vulnerable? Without dependable answers, it’s hard to prevent data leakage, enforce policy, or keep unauthorized deployments from undermining system integrity.
What Tenable Research Is Seeing in the Wild
Tenable’s research points to a clear trend: many security teams have found AI software operating in their environments without formal approval, a sign that standard provisioning is being bypassed. In a recent observation window, Tenable recorded more than 9 million instances of AI applications touching over 1 million hosts. That’s a lot of activity to track, and it’s growing.
At the same time, vulnerabilities tied to AI continue to rise. The volume and variety of issues demand a programmatic approach—discover what’s there, assess it quickly, and prioritize fixes that reduce risk across the most critical systems first.
Where Vulnerabilities Are Showing Up
Tenable has identified weaknesses in popular AI solutions, including widely used platforms such as Microsoft Copilot and Flowise. The takeaway isn’t that AI is unsafe by default; it’s that these tools are software like any other and need the same rigor: frequent assessments, prompt patching, and continuous monitoring so gaps don’t linger unnoticed.
What AI Aware Brings to the Table
AI Aware applies a proactive, layered approach to AI security. It blends several assessment techniques—agent-based monitoring for deep host-level insight, passive network analysis to see what’s actually talking to what, dynamic application security testing to probe behavior, and broad scanning to cover large estates. Used together, these methods help surface both sanctioned and unsanctioned AI software, along with their supporting libraries and plug-ins, and the vulnerabilities attached to them.
With that visibility, teams can cut off easy exploitation paths, reduce the chance of sensitive data leaking through misconfigurations or risky extensions, and rein in unwanted compute consumption from rogue or poorly configured AI services. It’s about turning scattered findings into clear, actionable steps.
Dashboard, Context, and Ongoing Monitoring
AI Aware includes an integrated dashboard that shows which AI software is most prevalent across your environment and flags critical assets with AI-related weaknesses. That overview makes it easier to focus on what matters first and track progress over time as fixes land.
- Shadow Software Development Detection that brings to light unexpected AI development components present within an organization. This helps surface unreviewed SDKs, models, or build-time plug-ins that quietly crept into pipelines so they can be evaluated and, if needed, removed or brought under policy.
- Finding Filters to streamline AI detection during vulnerability assessments, ensuring teams can focus on the most pressing AI-related vulnerabilities using Tenable's Vulnerability Prioritization Rating (VPR). Filters sharpen the signal, so high-impact issues bubble to the top instead of getting buried in long lists.
- Asset-Centric AI Inventory detailing inventories of AI packages, libraries, and browser extensions, enriching the management of AI-related assets. By tying findings to specific hosts and applications, teams can assign ownership, plan remediation, and verify that changes actually reduce risk.
What’s Next and How to Engage
Tenable is continuing to invest in AI security. An upcoming webinar, "Mitigating AI-Related Security Risks: Insights and Strategies with Tenable AI Aware," will share perspectives on the evolving AI threat landscape and practical approaches for managing it. The session aims to equip participants with steps they can take now, plus guidance on building a durable program as AI usage expands.
About Tenable
Tenable focuses on exposure management—finding and closing the security gaps that erode business value and trust. Its AI-driven platform provides a unified view of risk across attack surfaces so organizations can strengthen defenses with context and prioritize the fixes that matter most. With a global customer base of more than 44,000, Tenable’s mission is to help enterprises reduce vulnerability and operate with confidence in an environment that keeps changing.
Frequently Asked Questions
What is Tenable AI Aware, in plain terms?
AI Aware is Tenable’s capability for discovering where AI shows up in your environment, identifying the related vulnerabilities, and helping you prioritize remediation. It focuses on AI applications, frameworks, tools, libraries, and plug-ins—both the ones you approved and the ones that slipped in.
How does AI Aware actually find AI-related risk?
It combines multiple assessment methods: agent-based monitoring for host details, passive network analysis to see traffic, dynamic application testing to probe behavior, and broad scanning for coverage. Together, these techniques surface AI software and associated weaknesses so you can address exploitation risk, data leakage, and wasteful resource use.
What did Tenable’s research uncover about AI usage?
Tenable observed AI applications running without formal approval in many environments. In a recent period, it recorded over 9 million AI app instances across more than 1 million hosts. The pattern is clear: AI adoption is accelerating, often outside normal provisioning, which raises the need for visibility and control.
Which AI platforms have had vulnerabilities identified?
Tenable has highlighted vulnerabilities in widely used offerings such as Microsoft Copilot and Flowise. The key point is not to single out any one product, but to treat AI tools like other software—scan them regularly, patch quickly, and monitor continuously.
How can my team get started preparing for AI-related risks?
Begin by establishing visibility: inventory AI software and extensions, then use prioritization (such as VPR) to focus on the most consequential issues. Apply regular assessments, tighten approval processes to limit shadow deployments, and consider joining Tenable’s upcoming webinar for guidance on building an effective AI risk management approach.