Introducing the Agentic Control Plane for Exposure Management

Launched at Black Hat USA 2026: a new capability that governs AI-discovered vulnerabilities from scan to verified closure.
What we launched
At Black Hat USA 2026, Tuskira launched the Agentic Control Plane for Exposure Management, a new capability within the Tuskira platform that governs AI-discovered vulnerabilities from scan to verified closure. It extends our existing zero-day and exposure-response capabilities to frontier-model scanning, and it is available now.
The short version: Tuskira applies enterprise policy to AI and legacy scanner workflows, maps findings to the deployed environment, determines which exposures are reachable and undefended, applies approved compensating controls, routes the durable code fix, and re-tests the attack path to verify closure.
Why now: discovery has been industrialized
Frontier models are changing how vulnerabilities are discovered. They can surface novel flaws that legacy scanners may not detect, and those findings can arrive without a CVE, a CVSS score, a vendor patch, an exploit-maturity signal or an established owner. Enterprise vulnerability-management policies, SLAs and ticket-routing processes were built around exactly those artifacts.
The pace problem is measurable. In its May 22, 2026 snapshot, Tuskira Research found that AI-driven vulnerability discovery outpaced visible remediation by approximately 16.5×, with one AI-driven pipeline disclosing 1,596 verified vulnerabilities across 281 open-source projects in 63 days. At the same time, AI-assisted exploitation is compressing the window available to validate and respond.
A code finding is not production risk
An AI scanner can identify and validate a vulnerable path in source code. On its own, it cannot determine whether that code is deployed, reachable from the internet, protected by existing controls or connected to a critical asset. That is the difference between a code finding and production risk.
Many exposure-management workflows stop after discovery and prioritization. The Agentic Control Plane keeps going: once risk is validated, Tuskira turns it into a governed SOC workflow. The security operations team receives the exposure verdict and the immediate containment action, while the durable code fix is routed to the application or engineering owner.
How it works: inside the Exposure Response Loop

The Control Plane runs a four-stage Exposure Response Loop:
- Orchestrate. Route customer-authorized frontier models to the appropriate repositories and risk tiers, and normalize AI-discovered findings alongside legacy VM, SAST, SCA and cloud findings.
- Govern. Enforce model selection, repository and data scope, spending limits, approval workflows and retention policies, with a complete audit trail of what was scanned, by which model and why.
- Contextualize. Determine whether vulnerable code is deployed, reachable, undefended and connected to a breach path.
- Respond and verify. Apply approved compensating controls through WAF, EDR, IAM or network policy, route the durable code fix and re-test the modeled path to prove closure.
Context comes from more than 150 integrations across vulnerability management, application security, cloud, endpoint, identity, network controls, SIEM and IT service management. Findings, verdicts and actions are governed through customer-authorized connectors and data-scoping policies, so source code and vulnerability data remain within customer-authorized workflows under enterprise-defined retention and model-training terms.
What this looks like in production
In a global financial-services deployment, only 0.46% of 12.3 million raw findings required action, and exposure triage fell from three weeks to 30 minutes. That is the operating model the Control Plane extends to AI-discovered findings: fewer findings that matter, validated faster, closed with evidence.
"AI has industrialized vulnerability discovery. The new bottleneck is determining which findings create real production risk and closing them before a patch ships. Tuskira's Agentic Control Plane for Exposure Management governs how frontier models participate in enterprise security operations, validates reachability and defense coverage, and orchestrates response until closure is proven. Finding vulnerabilities is becoming commoditized. Closing the right exposure with proof is the product."
Piyush Sharma, CEO and co-founder, Tuskira
Available now
The Agentic Control Plane for Exposure Management is available now as part of the Tuskira platform. Request a Breach Resilience Assessment to see which exposures create reachable, undefended paths in your environment, and read The Emerging Patch Gap for the data behind the launch.


