SPOC updates
Discover what’s new — fresh updates just for you.
One AI. Different Rules.
On the Weight of Risk in an Organization
AI portfolios grow faster than an organization’s ability to govern them.
Each system carries a different level of risk, responsibility, and regulatory obligation.
Applying a single, universal rule set creates a double cost.
It overloads low‑impact systems while weakening oversight where AI affects people, money, or operational continuity.
The organizing decision is straightforward:
the risk class belongs to the system, not to a document.
In this article, I describe a mechanism in which a risk class stored in the system record connects regulations into a single operating model, in the spirit of our approach to Controlled Autonomy.
One AI, Four Regulatory Perspectives
AI systems often fall under multiple regulations at the same time.
The same system can be assessed in parallel from different regulatory angles.
- The AI Act classifies systems using a risk pyramid, from prohibited use cases through high‑risk systems to limited and minimal risk.
The classification depends primarily on the system’s purpose and the impact of its decisions. - NIS2 focuses on the criticality of the digital service supported by AI.
The same model may become part of a critical service if it affects continuity, security, or availability. - DORA concentrates on ICT resilience, dependencies on external providers, and incident response capability.
- GDPR evaluates whether a system makes automated decisions about individuals, particularly when those decisions produce legal or similarly significant effects.
As a result, the same AI model may simultaneously be classified as high‑risk under the AI Act, support a critical service under NIS2, trigger reporting obligations under DORA, and fall under GDPR due to automated decision‑making.
From smart to practical — because AI
should empower your teams
We design ServiceNow AI and automation solutions that simplify work and accelerate decisions.
These perspectives apply to the same system at the same moment.
A single risk class stored in the system record does not replace regulatory classifications. Instead, it organizes them into one operational representation and triggers the correct obligations.
Classification as a System Attribute
Classification starts working only when it stops being a spreadsheet.
In large organizations, the number of categories quickly becomes unmanageable. Each regulation introduces its own concepts, and each team adds additional labels. The result is more terminology, but less actual control.
The Risk Class Stored in the System
The risk class should live in the system record, where decisions, accountability, and evidence are created. This provides a single reference point for multiple classifications. The system has one risk class instead of several parallel assessments maintained in silos.
The system record shows the risk class, the Business Owner, the obligations derived from that class, and an evidence trail of changes with justification.
- Auditors see the current system state rather than a reconstructed history from spreadsheets.
- Teams see their scope of responsibility.
- Executives see where risk truly concentrates.
One Decision, Many Obligations
A single risk class can trigger obligations across multiple regulations at once.
The mapping exists in one place, and teams receive only the tasks relevant to their system.
A Class That Evolves
Risk changes over time. Retraining, new data, market expansion, or changes in user groups can alter the risk profile. Each of these changes should trigger reassessment.
When This Layer Is Missing
The early stages usually look familiar.
A new system follows an established process, and controls and interpretations are rebuilt from scratch.
Compliance begins to live in multiple places at once.IT holds logs.
Legal holds justifications. Risk maintains requirement lists.
During a crisis, the organization manually assembles a single response.
A single rule package is always designed for the average, not for extremes.
As the number of systems grows, costs rise: the same questions return, the same decisions repeat, and evidence scatters across locations.
The Incident as a Moment of Truth
In an incident, time and consistency matter.
First, the organization must determine what the incident concerns.
Then it must identify which obligations and reporting timelines apply.
Delays increase the risk of formal errors and inconsistent communication.
A uniform rule set produces excessive control.
Low‑impact systems receive safeguards that are too heavy, while high‑impact systems receive safeguards that are too light.
Costs increase, risk spreads unevenly, and AI development slows under growing complexity.
From System to Risk Class
Classification must be embedded in the workflow.
Assessment Before Production
Every system should undergo assessment before going live.
Without an assigned risk class, it does not enter production.
The class is derived from five variables: system purpose, data sensitivity, decision impact on people or finances, level of autonomy, and the affected user group.
These variables define the risk class, and the class determines inherited controls and required evidence.
Inheritance of Obligations
The class translates into regulatory obligations.
Each obligation has an owner and required evidence.
Higher classes require broader oversight, while lower classes operate under lighter regimes.
Reclassification Over Time
System changes should trigger reassessment. Moving to a higher class requires Business Owner approval, and everything remains visible in a single system record.
When the Class Starts the Clock
During an incident, multiple regulatory clocks run in parallel.
The same event may trigger different reporting obligations: AI‑related reporting, ICT incident reporting, critical service notifications, or personal data breach reporting.
These are distinct obligations, sent to different recipients, and supported by different evidence.
When the risk class is part of the system record, the correct protocol activates automatically.
Notifications reach the right owners, and the evidence trail grows with each action.
The goal is for technical and regulatory tracks to start in parallel, without improvisation.
Four Questions That Bring Order
Before an AI system enters production, the organization needs four answers:
- What is the system’s risk class?
- Which regulations apply?
- What controls result from this combination?
- Who has the authority to change the classification?
These answers become the entry condition for production and the reference point for every system change.
Each regulator looks at the same AI from a different angle. Classification connects these views into a single mechanism: the system has a class, the class triggers obligations, and obligations create evidence.
Where This Lives in the Platform
This is exactly the kind of mechanism ServiceNow’s risk and resilience tools are built to operationalize. Integrated Risk Management (IRM) connects regulatory frameworks to controls and continuously monitors risk across critical services, so a single risk class can map to obligations under the AI Act, NIS2, DORA, and GDPR without four separate tracking efforts. The Smart Assessment Engine pre-qualifies AI systems at intake and can auto-approve low-risk cases, freeing governance teams to focus on the systems that actually carry weight. And AI Control Tower extends this further, giving organizations a single place to monitor AI system health, scoring, and risk posture across the entire AI portfolio.
In other words, the system record this article describes isn’t a theoretical construct. It’s the natural shape of GRC and IRM on the Now Platform, when AI governance is treated as a workflow rather than a document.
Why SPOC?
At SPOC, we set new standards in information security, business continuity, crisis management, and cybersecurity. Our process optimization is built on two key pillars: internationally recognized best practices and full digitalization through the ServiceNow platform.
Best Practices and Standards
We align with global standards to ensure the highest quality and effectiveness.
Digitalization and Integration
We digitalize and automate security processes using ServiceNow modules, delivering seamless integration and enhanced management practices.
ServiceNow Expertise
Our experts combine deep subject-matter knowledge with advanced ServiceNow skills, allowing us to create solutions tailored to your needs.
Operational Excellence
By integrating with ServiceNow, we improve visibility, control, and response times — boosting your organization’s operational efficiency.
Complex end-to-end ServiceNow solutions
After Knowledge 2026: A New Reality for Enterprise AI
ServiceNow Knowledge 2026 made one thing very clear: we are looking at the same shift from different but equally important angles. Below are two perspectives from our leadership team. First, Karol shares a CEO view on how AI is reshaping enterprise strategy. Then Adam adds a CPO lens focused on platforms, products, and execution.
Karol’s perspective
Back from ServiceNow Knowledge 2026, and one thing is clear: we are entering a completely new phase of enterprise technology. AI is no longer an innovation discussed in isolated use cases. It is becoming a native layer of every workflow, every platform, every business decision. Here are my 5 biggest takeaways from this year’s conference.
1. AI is not an add-on
A few years ago, AI in ServiceNow meant Predictive Intelligence and a handful of GenAI capabilities. Today, we are talking about hundreds of AI skills, AI agents, agentic workflows, orchestration layers and AI-native integrations across enterprise platforms. The biggest realization? Every new workflow introduced today will eventually become AI-augmented. AI is no longer something companies “add later.” It is becoming a default architectural layer of enterprise operations.
2. Data governance matters
As AI adoption accelerates, data quality becomes critical. AI agents exchange information at a speed and scale impossible to govern manually. Integrations between platforms like ServiceNow, SAP, Salesforce or Workday will increasingly involve AI talking to AI. Error handling alone will not be enough anymore. Organizations will need strong data governance, ownership models and architectural discipline from the very beginning. The companies that succeed with AI will not necessarily be those with the most tools, but those with the cleanest and best-governed data.
3. AI is democratizing software creation
We used to talk about Generative AI because AI was generating content. What we are seeing now is something bigger: AI is enabling people to create entirely new things. Employees can build workflows, design interfaces, generate reports, analyze data and prototype applications without traditional technical specialization. This reminds me of what happened when smartphones put cameras in everyone’s pocket. The volume of digital creation exploded. The same is now happening in enterprise software. More ideas, more automation and more innovation will be created in the next few years than ever before.
4. AI Control Tower is a must
One of the most interesting announcements for me was AI Control Tower. The best way to describe it is simple: it is becoming a CMDB for AI. As organizations adopt more agents, automations and AI-generated assets, they will need visibility into what access it has, which data is being exchanged, what risks exist and how AI systems interact with each other. Traditional governance methods will simply not scale to the speed of AI-driven operations. Enterprises will need platforms capable of governing AI with the same intelligence and speed as the AI itself.
5. AI Platform needs a smart strategy
The pace of innovation is becoming overwhelming — even for experienced IT leaders. And now imagine what this means for Platform Owners, Product Owners or ServiceNow CoEs. When employees can create new features and workflows in days instead of months, platform governance can no longer rely on quarterly steering meetings or ad-hoc advisory boards. Governance must become a living operational capability. Organizations will need clear platform strategies, fast decision-making processes, roadmap ownership and dynamic governance models that guide innovation without slowing it down. Democratization without direction quickly becomes chaos.
The biggest takeaway from Knowledge 26?
The AI era is not only changing technology. It is changing how enterprises must think about architecture, governance, ownership and innovation itself.
Adam’s perspective
Building on what Karol already shared after #ServiceNow #Knowledge2026, this was probably the most intensive Knowledge conference I have attended so far… and I believe it was my 8th one already.
The amount of new products, acquisitions, AI capabilities, and the overall pace of change is simply astonishing. Even for experienced platform leaders, it can sometimes feel overwhelming.
That is exactly why, as SPOC, we need to stay ahead of this transformation – not only to understand the technology itself, but to help our customers translate innovation into pragmatic business value.
Here are some of my biggest takeaways from this year’s conference:
1. Moveworks is redefining the enterprise entry point
One of the most interesting shifts is how conversational AI is becoming the new front door to enterprise services. Employees increasingly expect natural interactions instead of navigating complex portals and workflows. The combination of ServiceNow and Moveworks shows a very clear direction: AI is becoming the operational interface between users and enterprise platform.
2. Otto shows where enterprise AI is heading
“Otto” was another strong signal of how ServiceNow sees the future of platform intelligence. We are moving toward contextual, embedded AI that does not simply assist users, but actively participates in operational execution, decision-making, orchestration, and workflow optimization. AI is becoming part of the platform fabric itself.
3. EmployeeWorks is helping connect the entire experience layer
One of the most interesting observations for me was how EmployeeWorks brings together workflows, AI, enterprise search, communication, and employee interactions into one consistent experience layer. ServiceNow is clearly moving toward a model where employees no longer need to understand organizational silos or platform boundaries. The platform itself becomes the orchestrator of work across the enterprise.
4. Build Agent makes AI-assisted development feel real
Build Agent was one of the most impressive demonstrations for me. It shows how ServiceNow is moving from low-code toward AI-assisted creation, where users can describe what they want to build and quickly turn ideas into working prototypes. The “vibe coding” experience was not just a concept – it actually worked, and it showed how much faster platform teams may be able to design, validate, and deliver new capabilities in the future.
5. The long-term platform strategy is becoming very clear
What stands out to me is how ServiceNow is building an end-to-end enterprise ecosystem around AI, workflows, governance, security, and operational intelligence. The direction shaped through capabilities such as AI Control Tower, together with acquisitions and partnerships involving companies like Moveworks, Logik.ai, data.world, Veza, and others, creates a very coherent long-term vision. ServiceNow is evolving into an AI Control Tower for business reinvention.
My biggest takeaway from Knowledge 2026?
We are no longer talking about isolated AI use cases or standalone automation initiatives. We are witnessing the emergence of fully integrated enterprise operating platforms where workflows, AI, governance, automation, security, and data strategy are becoming one coherent ecosystem.
Why SPOC?
At SPOC, we set new standards in information security, business continuity, crisis management, and cybersecurity. Our process optimization is built on two key pillars: internationally recognized best practices and full digitalization through the ServiceNow platform.
Best Practices and Standards
We align with global standards to ensure the highest quality and effectiveness.
Digitalization and Integration
We digitalize and automate security processes using ServiceNow modules, delivering seamless integration and enhanced management practices.
ServiceNow Expertise
Our experts combine deep subject-matter knowledge with advanced ServiceNow skills, allowing us to create solutions tailored to your needs.
Operational Excellence
By integrating with ServiceNow, we improve visibility, control, and response times — boosting your organization’s operational efficiency.
Complex end-to-end ServiceNow solutions
The AI Digital Passport
A governed AI system is defined by the mechanisms that keep it valid — not by the parameters assigned at deployment. As operational contexts shift, the primary task of Workflow Architecture is to prevent Authorization Decay by continuously verifying the system’s Right to Act. The Digital AI Passport moves governance from static visibility to active enforcement, ensuring that autonomy is a verified state, not a permanent grant.
Registration vs. Continuous Governance
Registration is a timestamp. An AI Inventory (CMDB) records starting conditions: Owner, Purpose, and Expiry Date. These are necessary, but they only capture a moment. As data changes and business assumptions evolve, those parameters degrade. The gap between the deployment record and current reality is where risk accumulates. Registration is a documented starting point; Governance is the continuous verification that those conditions still hold.
Authorization Decay
AI authority decays through Data Drift and changing business environments — a different failure mechanism from traditional software. A system running on parameters defined six months ago carries Stale Authorization: a deployment-time snapshot treated as a permanent grant. Authorization Decay is the default state of any unmonitored system. Lifecycle Control is the architectural response to this operational gap.
The Digital AI Passport
The Digital AI Passport is a Lifecycle Control Layer embedded in the CMDB. It operates through three Safety Interlocks:
- [OWNER] Certified Accountability: A named individual with authority to intervene.
- [PURPOSE] Operational Boundary: The defined scope of authorized decisions, enforced as the active limit of system action.
- [EXPIRY] Validity Window: The time-bounded condition that triggers mandatory re-evaluation.
An interlock breach transitions the system from [VALID] to [INVALID] — suspending the Authority to Act until the condition is verified.
Operating Model Assessment
& Transformation Blueprint
See where your current model supports the business well, where greater alignment is needed, and what should come next.
Mechanisms of Enforcement
Governance is operational only when failed conditions produce automated consequences via AI Control Tower:
- Algorithm Audit: Code review and bias verification are prerequisites for Authorization Renewal.
- Data Attestation: Periodic workflows confirming data accuracy. If confirmation is overdue, the system transitions immediately to [INVALID].
- Drift Detection: Monitoring behavior to trigger re-evaluation before failure occurs.
- Enforcement: Integrated with the GRC risk model, executing responses without manual intervention.
Audit Readiness as a System State
Audit readiness is a system state, not documentation. A governed AI system is always audit-ready because its current state—attestation logs, drift reports, and audit history — is continuously maintained and recorded. Evidence trails and the enforcement layer keep parameters valid in real-time. When an auditor asks for proof, the answer is the live system state available in the AI Control Tower at any point in time.
The Condition for Autonomous Action
Workflow Architecture defines who is authorized to act and under what conditions. The Digital AI Passport verifies whether those conditions remain valid in practice. The shift is from visibility (knowing what we have) to Enforcement (knowing which systems currently hold the Authority to Act).
A system in [INVALID] state does not act. This is not a restriction; it is governance working as designed. ServiceNow is the natural environment for this configuration, as it leverages the CMDB, GRC risk models, and the AI Control Tower to transform governance from a policy into a functional, enforceable system state. Authority without evidence is a choice to operate in a blind spot.
Why SPOC?
At SPOC, we set new standards in information security, business continuity, crisis management, and cybersecurity. Our process optimization is built on two key pillars: internationally recognized best practices and full digitalization through the ServiceNow platform.
Best Practices and Standards
We align with global standards to ensure the highest quality and effectiveness.
Digitalization and Integration
We digitalize and automate security processes using ServiceNow modules, delivering seamless integration and enhanced management practices.
ServiceNow Expertise
Our experts combine deep subject-matter knowledge with advanced ServiceNow skills, allowing us to create solutions tailored to your needs.
Operational Excellence
By integrating with ServiceNow, we improve visibility, control, and response times — boosting your organization’s operational efficiency.
Complex end-to-end ServiceNow solutions
Which AI Are You Already Using?
The first step in Controlled Autonomy: assigning the human in charge.
Your workflows are already making decisions. What is missing is the designated owner. Workflow Architecture defines the boundary between automation and accountability. In a landscape of accumulating AI logic, every automated outcome requires a verified human owner and a persistent evidence trail.
AI Decision Trail: Silent Accumulation
AI in your organization is a natural part of how systems evolve. These tools entered your processes gradually — through incremental updates and new vendor features. It has accumulated. This created a new category of assets: Ghost Workers. These are algorithms making real-world decisions that now require a formal place in your management structure and an official owner.
AI is already deciding, but control has often been a secondary thought. As these systems become part of your daily work, a new risk emerges: AI-driven decisions operating without a clear line of accountability.
A prime example is a healthcare company currently facing lawsuits over an AI system used for claims. In court, their defense depended on one thing: traceability. To succeed, they needed clear data:
- Who approved the logic?
- Who monitored it?
- Who held responsibility for the outcomes when results began to drift?
The struggle arose because the operating model had a gap. It lacked a mechanism to link the algorithm to a specific person and reconstruct how a decision was made at any point in time. This defines your next step. It is about taking real control over the decisions AI is already making.
Three Pillars of AI Governance
In smart processes, the focus shifts from managing tasks to managing decisions. Effective oversight relies on three pillars:
Clear Ownership
Every AI model must have a business owner. Responsibility for results is documented and visible.
Evidence
Compliance with rules like the AI Act requires full traceability. Every AI decision must leave a digital footprint (Digital Passport).
Service Visibility
Mapping AI within your service model (CSDM) provides full control over what is currently running and what value it brings.
This is the new reality. An Autonomous Enterprise requires every AI activity to be known and measured. This model builds oversight directly into your daily operations.
From Ghost Workers to Governed Assets
Five components — one direction: from unknown to owned.
- 01 — AI Intake: The entry point for every AI initiative. Whether a new proposal or a vendor update, each system passes through a qualification workflow to become a registered asset with a named owner and a unique identifier.
- 02 — AI Asset Register: Verification of ownership is the prerequisite for operation. Every system is linked to a service, a process, and a risk, making its impact traceable across the organization.
- 03 — Digital AI Passport: A living record of capabilities. It defines when the system operates autonomously and when it hands back control to a human. This structured record is your primary evidence for regulators and auditors.
- 04 — Service & Data Mapping: Integration with CSDM defines which data flows through the system and which services depend on its decisions—providing essential context for impact assessments.
- 05 — AI Control Tower: The governance layer on ServiceNow. It combines workflows and monitoring into a single control point, keeping ownership and execution aligned.
From Decisions to Evidence
Traceability is now a core part of the operating model. Every decision made by a registered system is linked to an owner, a model version, and a clear scope of authority. This is a live record of your AI operations.
When auditors or legal teams require explanations, the answers are ready by design:
- Who approved the logic.
- When it was last reviewed.
- Who was responsible for the results.
This approach provides clarity before the questions are even asked. Traceability gives your organization the power to explain its decisions, forming the foundation of institutional trust. ServiceNow is the natural environment for this control, as it aligns with the workflows and data already in place.
Operating Model Assessment
& Transformation Blueprint
See where your current model supports the business well, where greater alignment is needed, and what should come next.
Control That Runs Itself: Scaling the Human-in-the-Loop
As AI spreads, manual governance reaches its limits. This model uses the platform to extend the supervisor’s reach, keeping human judgment at the center:
Real-time Discovery
The AI Control Tower monitors the landscape, bringing every AI-driven decision into the light.
Dynamic Passports
Templates standardize low-risk AI, allowing scale without operational overhead.
Managed Intervention
Clear thresholds define exactly when human judgment is required.
The result is full visibility and accountability — built directly into the operating model.
The License to Act
Before deploying your next AI system, ensure you have four answers ready:
- How many AI systems are operating right now?
- Who owns each of them?
- Who is accountable for their decisions?
- Who is responsible for the outcome if they fail?
These four answers are the foundation of your control. The Digital AI Passport is where this visibility becomes operational. It is the tool that verifies the License to Act — a right that is earned through transparency.
Source: https://www.theguardian.com/us-news/2025/jan/25/health-insurers-ai
Why SPOC?
At SPOC, we set new standards in information security, business continuity, crisis management, and cybersecurity. Our process optimization is built on two key pillars: internationally recognized best practices and full digitalization through the ServiceNow platform.
Best Practices and Standards
We align with global standards to ensure the highest quality and effectiveness.
Digitalization and Integration
We digitalize and automate security processes using ServiceNow modules, delivering seamless integration and enhanced management practices.
ServiceNow Expertise
Our experts combine deep subject-matter knowledge with advanced ServiceNow skills, allowing us to create solutions tailored to your needs.
Operational Excellence
By integrating with ServiceNow, we improve visibility, control, and response times — boosting your organization’s operational efficiency.
Complex end-to-end ServiceNow solutions