AI has turned vulnerability discovery into an industrial-scale, always-on process. This guide is for network and infrastructure teams who have to respond, closing the gap with continuous CVE impact analysis, governed remediation, always-on compliance, and certificate lifecycle management under a shrinking validity window.
Learn how to get AI’s velocity in each of those areas without giving an agent unchecked access to production.
In 2026, two of the largest AI labs, working independently, reached the same conclusion within weeks of each other: AI-driven vulnerability discovery, run at scale across dozens of technology vendors, is now generally available capability, not a research preview. What was expected to take 6 to 18 months to proliferate reached general availability in months.
For an infrastructure team, the change is not abstract. Advisory volume is up, arriving faster and from more vendors at once, and the team size, tooling, and change process handling it have not grown to match. A CVE that used to show up once a quarter now shows up most weeks, sometimes from two or three vendors in the same estate at the same time. Triage that used to take an afternoon now has to finish before the next advisory lands.
The AI labs just showed why vulnerability discovery moved to machine speed. See why that’s a call to modernize your operating model.
Before machine-speed discovery, the enterprise patch cycle worked, not because it was good, but because the input rate was bounded. Advisories arrived at a cadence that scripts, runbooks, and manual coordination could absorb. A critical CVE took weeks to months to remediate fleet-wide, and the industry had quietly agreed to live with that.
That bound is gone. The same class of AI capability that accelerates defenders is now generally available to accelerate attackers. AI finds vulnerabilities in minutes. Vendors ship patches in hours. Most enterprises take weeks to deploy them across an estate spanning Cisco, Juniper, Arista, Palo Alto Networks, Fortinet, and the rest of a typical multi-vendor network.
The gap between disclosure and deployment is the new attack surface. If your largest vendor shipped a critical patch tomorrow, how long would it take to deploy across your environment, with proper validation and rollback? For most organizations, the honest answer is weeks to months.
Closing the deployment gap is not a matter of working faster inside the old model. A human reading every PSIRT advisory by hand runs out of hours before the backlog does, once two or three vendors disclose in the same week. A change advisory board that meets weekly cannot approve daily volume. A script written for one vendor’s CLI syntax does not extend to the next vendor without a rewrite – and a rewrite does not happen at the pace advisories now arrive.
What has to change is the operating model underneath it all: from periodic to continuous, from manual triage to automated reasoning, from validated-after-the-fact to governed by default. In practice, that shows up in four places:
Itential is the platform built for that model. The deterministic execution and governance layer – pre-checks, post-checks, rollback, RBAC, immutable audit trails – was built and hardened in production over more than a decade, on some of the most demanding networks in the world. FlowAI, Itential’s agent harness, adds the capability to reason through a CVE notice, a compliance drift, or an expiring certificate the way an experienced engineer would, then act through that same governed execution layer.
Every vendor disclosure triggers a manual scramble: someone reads the notice, interprets what it means for the organization’s specific environment, cross-references it against device inventory, and works out how many devices are genuinely affected. It’s judgment-heavy work that resists scripting – a CVE that affects one firmware version but not another, or only when a specific feature is enabled, doesn’t reduce to a pattern match. At today’s volume, thousands of high-severity advisories in a matter of months, this stops being an inconvenience and becomes the actual bottleneck the deployment gap is built from.
Agents built on the Itential Platform, using FlowAI, ingest and parse CVE notices from the National Vulnerability Database across vendors, reason about which products, versions, and configurations are genuinely affected, then cross-reference those findings against live device inventory – not a point-in-time export – to produce a precise, prioritized list of exposed devices. That reasoning runs against Golden Config, Itential’s structured definition of what a compliant device looks like for every vendor and region, so an advisory gets checked against the actual configuration standard a device is supposed to meet, not a generic version match.
A script can check a version string. It can’t read a PSIRT advisory’s conditional language, weigh whether a feature flag changes exposure, or reconcile inconsistent vendor terminology the way a reasoning system can. Once impact is established, the same governed process can initiate a validated fix via a Compliance Plan, Itential’s mechanism for running a check or a fix across thousands of devices in one operation, with role-based access, approval gates, and a full audit trail on every step.
It was always a reasoning problem wearing a scripting-shaped disguise.
See it in action: three governed FlowAgents finding, fixing, and reporting real vulnerabilities the same day Cisco released its new vulnerability-finding model.
A prioritized exposure list is only useful if what happens next is fast and governed. This is the second half of the operating model: reasoning identifies what’s exposed, governed execution is where the fix actually holds.
Governed execution on the Itential Platform doesn’t run through just one path – a FlowAgent can run a script, call an API, or trigger a full workflow, whatever the fix actually requires. Multi-step changes, like a software upgrade, run as one continuous governed sequence, so a CVE finding hands off directly into the fix with no gap in accountability between finding the problem and closing it.
One large financial services organization with early access to a Mythos-class model surfaced enough configuration and topology vulnerabilities to require an estimated 18 manually built remediation workflows in a single week, more than any team could realistically build and validate in that window. Rather than hand-build each one, they deployed FlowAI agents instead, and rolled out an agent that handled both a software upgrade and password rotation across multiple different vendors in days, not weeks.
This doesn’t replace your CAB or ITSM process, it executes it. Itential’s ServiceNow integration works both ways: a change ticket can trigger a governed workflow, or a FlowAgent can open the ticket, make the fix, and close it out with full evidence attached. ServiceNow still owns the process. Itential runs the change underneath it.
Every change follows the same steps, no matter how it’s triggered: check the device is in the expected state, apply the fix, confirm it worked. If it didn’t, roll back automatically before anyone has to notice something broke. The audit trail is just a byproduct of how the change ran, not an extra step.
Continuous compliance is the state where infrastructure is verifiably compliant with its own standards at every moment, not just when an auditor checks. It replaces the quarterly scramble – pull configs, diff against golden standards, chase down drift, hope the audit lands between cleanups – with policy enforcement built into every change as it happens. Not every deviation from a golden configuration is a violation; the judgment work is telling intentional variance from genuine drift, at scale, without missing real gaps or flooding a team with noise.
Golden Configuration, Itential’s structured definition of what a compliant device, controller, or cloud resource looks like, gets checked continuously against every device on the platform, with drift detected at the attribute level the moment it occurs. Compliance Plans run that check, and any needed fix, across thousands of devices in a single governed operation, producing one unified audit report across CLI-managed network devices and API-managed cloud services alike. Because this runs through the same governed execution engine that handles CVE work and certificate rotation, compliance isn’t a separate check bolted on afterward, it’s a property of every change the platform makes by default.
Every execution produces a structured audit record automatically: which devices were checked, which standards applied, which violations were found, what was fixed, and the before-and-after state for every device. These reports map directly to frameworks like SOX, HIPAA, PCI-DSS, and NERC-CIP, so audit prep becomes a report pull instead of a multi-week project.
One North American utility automated NERC-CIP compliance across 25,000+ devices – where non-compliance fines can run over $1M per day – with drift remediation down to minutes instead of hours or days.
For most infrastructure teams, certificate management runs on a spreadsheet and a calendar reminder: track expiry, rotate before it lapses, hope nothing gets missed during a busy quarter. That process was survivable when public TLS certificates lived a year or more. It isn’t survivable at the cadence the industry is moving toward.
| Effective | Maximum certificate lifetime |
|---|---|
| 2026 | 200 days |
| 2027 | 100 days |
| 2029 | 47 days |
The CA/Browser Forum, the industry body that sets validity rules for publicly trusted TLS certificates, has voted to shrink maximum lifetimes on this fixed schedule. At a 47-day maximum, rotation stops being an occasional maintenance task and becomes a standing operational rhythm, running continuously across every certificate in the estate, indefinitely. A spreadsheet and a calendar reminder can’t hold that cadence.
This capability is scoped to certificates on network and infrastructure devices – switches, routers, firewalls, load balancers – not the broader enterprise-wide TLS or code-signing certificate market, which dedicated platforms already serve well. Where Itential earns its place is the multi-vendor infrastructure estate, where visibility is fragmented and rotation historically required touching each vendor’s tooling separately.
Agents built on the Itential Platform continuously inventory certificates across the multi-vendor estate: issuance date, expiry, issuing authority, and the device or service each one authenticates. That inventory runs on Lifecycle Manager, so status is never a static snapshot – it reflects current state across CLI, NETCONF, RESTCONF, and API-managed devices alike. Agents prioritize by actual risk and time-to-expiry, surfacing what needs attention this week versus what can wait. Rotation runs through the same pre-check, install, post-check, rollback discipline as any other governed change, with an audit record produced automatically.
One large insurance provider saw an 85% reduction in change-related incidents after moving to pre- and post-validated certificate rotation.
CVE impact analysis, fixing, continuous compliance, and certificate lifecycle management are four different problems with four different audiences. They also run on one platform architecture, proven in production over more than a decade.
Reasoning over a CVE, fixing an issue, enforcing compliance, rotating a certificate – all of it depends on the premise that AI agents can be trusted to act on production infrastructure. That trust is engineered into the security and governance layer, not assumed.
Scripts automate individual tasks. They don’t reason about unstructured advisories, coordinate validated action across a multi-vendor estate, or produce audit evidence as a byproduct of running. Generic AI platforms and agent frameworks reason well, but they weren’t built with the non-functional characteristics infrastructure operations require by default: pre-checks and rollback on every action, RBAC and GBAC enforced identically for humans and agents, immutable audit trails, zero data retention. Building that governance layer independently is possible. It’s also years of hardening, not a sprint.
A decade of governed execution is already the foundation underneath it.
Compressed software upgrade cycles from 6 hours to under 20 minutes across its network estate.
Stood up 5 FlowAgents in 4 days for service provisioning.
Using AI agents to take governed, deterministic action on infrastructure: reasoning through a goal using live infrastructure context and a scoped set of tools, then executing through the same governed engine that runs every other change. Agentic never means less governed.
Scanning identifies known weaknesses. Impact analysis determines which specific devices, versions, and configurations in a specific network are actually affected – reasoning across unstructured, vendor-specific language rather than a pattern match.
At minimum, a way to reach the devices in scope (CLI, API, or an existing management platform) and some source of device inventory, even an imperfect one. Organizations without a clean source of truth typically start with a smaller device group or a single vendor, prove the pattern, then expand.
No. The platform operates on zero data retention. No copies of customer configurations, telemetry, or operational data are created, and none of it is used to train AI models.
See how Itential connects AI reasoning to governed execution across your entire infrastructure. The fastest way to evaluate any of this is against a real CVE, a real compliance standard, or a real certificate inventory – bring your security team.