top of page

Tuskira Launches Agentic Control Plane to Govern AI-Discovered Vulnerabilities

  • 25 minutes ago
  • 2 min read

The exposure management platform connects frontier-model security findings with production context, automated defenses and verified remediation.


Tuskira has launched an Agentic Control Plane for Exposure Management designed to help enterprises govern vulnerabilities discovered by artificial intelligence and move them from initial detection to verified closure.


Introduced at Black Hat USA 2026, the new capability addresses a growing problem for security teams: frontier AI models can uncover software flaws that lack the traditional signals used by vulnerability management programs, including CVE identifiers, CVSS scores, vendor patches and exploit-maturity data.


Tuskira’s platform evaluates whether AI-discovered vulnerabilities exist in deployed systems, can be reached by attackers, lack effective defenses or connect to critical assets. The company then applies enterprise-approved compensating controls, assigns the permanent code fix and tests the attack path again to confirm that the exposure has been closed.


The Agentic Control Plane combines findings with production data from more than 150 integrations spanning application security, cloud infrastructure, endpoint protection, identity, network controls, SIEM platforms and IT service management systems.

Tuskira said customers can define which AI models may be used, what repositories they can access, how data is retained and which actions require approval. Vulnerability and source-code data remain inside authorized workflows and are not used to train third-party AI models, according to the company.


The launch comes as AI-assisted vulnerability research accelerates the rate at which previously unknown software flaws are identified. Tuskira Research reported in May 2026 that AI-driven discovery was outpacing visible remediation by roughly 16.5 times. One AI-powered research pipeline reportedly disclosed 1,596 verified vulnerabilities over 63 days.


The challenge is that identifying vulnerable code does not automatically establish business risk. Security teams must still determine whether the affected code is running in production, exposed to the internet, protected by existing controls or connected to sensitive systems.


“AI has industrialized vulnerability discovery. The new bottleneck is determining which findings create real production risk and closing them before a patch ships,” said Piyush Sharma, CEO and co-founder of Tuskira. “Tuskira’s Agentic Control Plane for Exposure Management governs how frontier models participate in enterprise security operations, validates reachability and defense coverage, and orchestrates response until closure is proven. Finding vulnerabilities is becoming commoditized. Closing the right exposure with proof is the product.”


Tuskira said one global financial-services deployment reduced 12.3 million raw security findings to 0.46 percent requiring action, while cutting exposure triage time from three weeks to 30 minutes.


The Agentic Control Plane for Exposure Management is available now within the Tuskira platform.

bottom of page