Axonius Asset Cloud is enhanced with AI-ready data foundation

Teju Shyamsundar
Principal Manager, Product Marketing, Axonius

Hadas Schlessinger
Director of Product Management, Axonius

AI has arrived, in production, for real. Security and IT teams are running AI-powered detection. Security analysts are investigating alerts in minutes instead of hours. Autonomous AI agents are in the early stages of running remediation workflows that used to require a human-in-the-loop. There’s no question about whether or not AI belongs in security operations. It’s already here. But, AI is only as good as what it can see.
Every action (human-driven or AI-driven) operates on data. In the context of asset intelligence, that means every device, user, application, cloud workload, operational technology (OT) sensor, and the exposures that exist across the attack surface. If that inventory is incomplete, outdated, or siloed across tools that don’t talk to each other, AI only compounds those issues. At machine speed, bad data proliferates faster than any security and IT team can catch.
Only 45% of organizations say they consolidate asset and exposure data into a single view (Axonius Actionability Report 2026), which means most AI initiatives are being built on a foundation that hasn’t been verified.
Asset intelligence is the prerequisite for any AI security strategy. It’s the layer everything else runs on. This week, we’ve announced updates to the Axonius Asset Cloud that align with that idea: give your security and IT teams a current, authoritative, and continuously reconciled picture of their environment and make it queryable from wherever the work happens.
Here’s what’s new across the Axonius Asset Cloud.
Bring your own AI, or use ours
Security and IT teams are moving beyond chat-based assistants to agentic workflows that reason across systems and coordinate action from investigation through remediation. To do that effectively, those tools need trusted context.
This week, we advance that on two fronts. We’re opening the Axonius Asset Cloud to the AI tools you already use and delivering our own intelligence natively. Announced today in early access, Axonius MCP Server makes the entire Axonius asset model (assets, software, exposures, relationships, ownership, and coverage) queryable in natural language from the AI tools your security and IT teams already use. Because Axonius has already collected, correlated, and reconciled the data, the Axonius MCP Server exposes a foundation that’s decision-grade.
Announced today in preview, Axonius AI Agent is the complementary side: a native, context-aware security partner that understands your environment as deeply as the analysts who run it, and respects your existing role-based access control (RBAC) so it never becomes a backdoor to sensitive data. Ask where endpoint detection and response (EDR) coverage has gaps or which devices are missing from the configuration management database (CMDB), and it returns the answer with recommended remediation.
Read more about the Axonius MCP Server and Axonius AI Agent.

Getting started with the Axonius AI Agent
Operating on asset truth: what’s new in Axonius Cyber Assets
If AI is only as good as what it can see, then the asset foundation is where trust is won or lost. Today, we are advancing three capabilities for Axonius Cyber Assets that turn raw inventory into durable, decision-grade context: high-confidence asset data that you can defend, business context that drives asset clarity, and a workspace that keeps your CMDB honest.
Verified Assets: high-confidence data to support your security operations workflows
Announced in April in preview and now available in early access, Verified Access provides an accurate count of cyber assets, with each one marked verified or unverified. The premise is simple: not all assets in an environment are equal from a data-quality standpoint. Some records are recent, corroborated across multiple sources, and stable. Others are ephemeral, stale, or carry duplication risk. When low confidence records flow into security workflows, risk-models, and metrics tracking, one bad record usually doesn’t stay isolated. It propagates, and at scale those errors compound.

Since our preview announcement, we’ve continued to make the model more precise. Assets now carry a high-confidence or low-confidence state, determined by configurable asset confidence settings.
High-confidence assets are the ones which have passed all confidence settings. Low-confidence assets still pass through the full Axonius data pipeline and correlation model, which means they aren’t discarded, but they don’t yet meet the confidence bar you’ve defined. For each one, Axonius surfaces exactly why the asset fell short, so the confidence gap gets fixed, not forgotten.
Asset confidence settings
Each asset is evaluated against four independent settings that, under the hood, are driven by Axonius’ asset intelligence data pipeline. You can control the policy values behind each one, and can tune them to your environment:
Recency: Only include devices with recent network activity. Stale or decommissioned records don’t inflate your active inventory.
Identity: Only include devices that carry sufficient identifier detail, like IP address, MAC address, serial number, cloud ID, etc.
Instability: Exclude “ghost” records that lack cross-adapter correlation detail. Removes devices seen only briefly within a narrow window. This prevents temporary or transient data like highly ephemeral servers or temporary networks.
Low-fidelity exclusion: Exclude single-sourced records that arrive from adapters notorious for inaccurate data.
Assets that clear all four are marked as high-confidence. Assets that miss one or more are marked as low-confidence, with the specific reason(s) identified, and routed to a triage view where the failure points back to the responsible adapter or data source for targeted remediation.
Ready to try it out? Reach out to your account team to enable Verified Assets in early access. Verified Assets will be generally available to customers in August 2026.
Business Context: retire the tags, custom fields, and naming hacks
Security programs run on asset characteristics that are rarely standardized across tools: is this endpoint active or retired? Managed or unmanaged across all endpoint tools? Does it belong to finance or engineering? Security teams have historically answered those questions with workarounds like custom fields, custom naming conventions, or tags (depending on separate asset management tools that each hold a slice of the answer in a silo). None of it holds up at scale.
Announced in April and now generally available, Business Context formalizes these characteristics as first-class, indexed characteristics on every device, drawn from the adapters already connected to the Axonius Asset Cloud. It spans three dimensions:
Lifecycle state: Active, inactive, ephemeral, decommissioned, and new.
Management posture: Managed, unmanaged, and out of scope.
Business unit: Organizational owner and defined by your own login (geo, department, etc).
CMDB Reconciliation Workspace: end the drift
In practice, security and IT teams both rely on the configuration management database (CMDB). In reality, neither of them trust it. Updates happen in batches or manual CSV uploads, discovery tools only see what their own scanners reach, and the result is constant data drift. Assets that exist in reality but are missing from the CMDB; records marked retired that are, in fact, still on the network; mismatched identifiers and inconsistent data fields for an individual asset; and data fields that are entirely missing from an asset. Decisions made on that data are slow and error-prone.
Announced today in early access, the CMDB Reconciliation Workspace treats Axonius as the reconciliation layer above your enterprise stack. Rather than replacing your CMDB, it continuously compares your CMDB against the correlated truth that Axonius assembles from every connected adapter, and surfaces the discrepancies as an observability layer you can act on.
With reconciliation rules, you define the scope of what you’re reconciling (which assets, environments, and conditions are in play), so you’re comparing the records that actually matter. It goes beyond asset presence, too. The CMDB Reconciliation Workspace surfaces mismatched or missing field values, like a hostname that exists in Axonius, but is blank in ServiceNow.
Here’s how security and IT teams can use it:
The Day-1 reconciliation audit: An analyst connects the ServiceNow adapter to Axonius and checks the CMDB Reconciliation Workspace. Within minutes, it flags assets present in Axonius, but missing from ServiceNow (“ghost assets”) and status mismatches (records marked retired in ServiceNow that are still active). An analyst selects the ghost assets, runs a “Create in ServiceNow” action via the Axonius Action Center, and closes an inventory gap that would have otherwise taken weeks of manual verification across security and IT teams.
Drift control: Because reconciliation runs every discovery cycle, hostnames, MAC addresses, and lifecycle states stay aligned between systems. The CMDB that your IT team depends on reflects the most current state of the network.
Ready to try it out? Reach out to your account team to enable CMDB Reconciliation Workspace in early access.

When business context actually drives prioritization: what’s new in Axonius Exposures
We’ve been outspoken about how exposure risk should really be measured. Severity scores alone do not give you the full picture. It’s a combination of the exposure itself, the asset it sits on, and how critical that asset is to the business. Today, we’re advancing two capabilities that give our prioritization engine that context.
Announced in April as generally available, Asset Criticality Management has been further enhanced. Asset Criticality Management enables organizations to define how critical each asset is to the business, so exposures on the systems that hold personally identifiable information (PII) or run revenue-critical workloads are automatically prioritized above equivalent findings on low-criticality assets.
Announced today and generally available in August 2026, the Asset Aware Threat Intelligence Feed is a new view of Axonius Threat Intelligence that instantly correlates each newly published threat to every impacted asset type that Axonius discovers (endpoints, containers, images, code repositories, and more) with recommended fixes. The drag between “threat published” and “full impact understood” collapses from days to seconds.
Read more about the updates to Axonius Exposures that help organizations fight operational drag.
Building momentum with IoT and OT: Cyber-Physical Assets
Much like security and IT systems, cyber-physical systems are not exempt from the AI wave. At Hannover Messe 2026 in Germany, Rockwell Automation showcased AI-powered autonomous operations and Schneider Electric unveiled agentic manufacturing capabilities in partnership with Microsoft. The AI push is expanding the cyber-physical footprint faster than ever. Because automation needs broadly-scoped permissions to deliver its full benefit, it’s widening the blast radius along with it. All of this lands on top of the already-existing challenge of discovering and hardening IoT and OT devices in the first place.
With 96% of OT incidents starting from an IT compromise, it’s critical to have strong security controls across both IT and OT, along with a unified, correlated view of assets and their relationships. Axonius Cyber-Physical Assets closes that gap: continuous, real-time visibility into every connected cyber-physical asset (including AI-enabled ones) so security teams can identify unmanaged or misconfigured devices before attackers exploit them, and correlate that exposure across the broader IT/OT/IoT ecosystem.
Announced in April in early access, Axonius Cyber-Physical Assets continues to be available in early access and has been refined in partnership with several Fortune 500 customers across industries.
Ready to try it out? Reach out to your account team to enable Cyber-Physical Assets in early access. Cyber-Physical Assets will be generally available for customers in the second half of 2026.
Go from version drift to enforceable policy: what’s new in Axonius Software Assets
Outdated software is one of the most preventable sources of risk, but continues to be one of the toughest challenges to manage at scale. Security and IT teams alike know they need to enforce version standards, but without a clear picture of what’s running and how far behind it is, policy stays aspirational.
Announced in April and now generally available, Software Version Rank scores every software version by how current it is (or isn’t). The newest version is rank 0, the one before it is rank 1, the one before that is rank 2, and so on. Axonius recalculates these ranks every discovery cycle, so as new versions show up, everything is sorted automatically. Instead of reading version strings and cross-referencing across vendors, you get a single number that tells you how far behind each install has fallen.
How security and IT teams use it:
Enforce an N-x policy automatically: Instead of maintaining lists of “approved” version strings that go stale each time a vendor ships an update, write the policy once: flag anything where Software Version Rank is greater than 2 to enforce “no more than two versions behind.” Utilize that query in the Axonius Action Center to notify owners, open tickets, and track remediation, so that N-x policies are actively enforced, not just monitored.
Right-size and consolidate: Security and IT teams work from the same ranked view to spot where multiple, outdated versions of the same title are running across the estate, then drive consolidation before it becomes an audit finding.

Asset intelligence is where AI-driven security starts
We’ll continue this line on repeat: AI doesn’t work without the fundamentals. The attack surface is expanding faster than security and IT teams can track manually. Cloud workloads spin up and disappear in hours, SaaS and AI adoption has accelerated beyond IT’s line of sight, and AI is supposed to close that gap. It will, but only if it’s working from a foundation of truth.
Everything we’ve covered in this blog serves that foundation. Verified Assets gives you data you can defend. Business Context makes your inventory legible and durable. The CMDB Reconciliation Workspace keeps your system of record honest. Software Version Rank turns software drift into enforceable policy.
Exposures updates in Asset Criticality Management and the Asset Aware Threat Intelligence Feed make prioritization reflect real business risk. And, the Axonius MCP Server and Axonius AI Agent make all of this queryable, including with the AI tools your security and IT teams are already adopting.
The organizations that will extract the most value from AI security are the ones that build the foundation first, before, or alongside, the AI tools they’re deploying.
Ready to experience asset intelligence in your environment? Get a demo.
Availability
Axonius AI Agent is in preview. Axonius MCP Server is available to customers in early access.
For Axonius Cyber Assets:
CMDB Reconciliation Workspace and Verified Assets are available to customers in early access. Verified Assets will be generally available to customers in August 2026.
Business Context is generally available to customers.
For Axonius Exposures:
Asset Criticality Management is generally available to customers.
Asset Aware Threat Intelligence Feed will be generally available to customers in August 2026.
For Axonius Cyber-Physical Assets, this solution remains in early access and is expected to be generally available in the second half of 2026.
For Axonius Software Assets, Software Version Rank is generally available to customers.
Additional Resources
Read the press release to learn more about the new capabilities across Axonius Cyber Assets, Axonius Exposures, Axonius Cyber-Physical Assets, and Axonius Software Assets.
Read the press release and blog to learn more about the Axonius AI Agent, Axonius MCP Server, and Docs for AI.
Read the blog to learn more about how asset intelligence is no longer optional in the AI era.

Get Started
See how to make asset intelligence actionable with a guided demo:
- Stop chasing data — work from one asset model your entire team can trust.
- See what's exposed before it's a problem — surface coverage gaps automatically.
- Turn alert noise into action — cut thousands of alerts down, to the ones that matter.
