
Tuskira introduced an Agentic Control Plane for Exposure Management, a new layer in its platform that automates handling of AI-discovered vulnerabilities from initial scan to confirmed fix.
The system connects over 150 integrations across vulnerability management, application security, cloud, endpoint, identity, network controls, SIEM, and IT service management. It maps raw findings against production environments, filters for exposures that are reachable and undefended, applies compensating controls, routes code fixes, and retests attack paths to verify closure.
How the control plane works
Advanced AI models detect flaws that traditional scanners miss, often without a CVE, CVSS score, or vendor patch. This leaves enterprise vulnerability-management teams without the usual artifacts for prioritizing and routing tickets. Meanwhile, AI-driven exploitation reduces the time available to validate and respond.
A May 22, 2026 snapshot from Tuskira’s internal research showed AI-driven discovery outpaced visible remediation by about 16.5 times. One pipeline identified 1,596 verified vulnerabilities in 63 days. The full methodology appears on the company’s research site.
An AI scanner might flag a vulnerable code path but cannot determine if that code is deployed, exposed to the internet, or protected by existing controls. Tuskira’s control plane addresses this by processing findings through a four-step Exposure Response Loop:
- Orchestrate: Normalize AI-discovered findings alongside legacy vulnerability-management, SAST, SCA, and cloud findings, then direct authorized models to the correct repositories and risk tiers.
- Govern: Enforce model selection, repository access, data scope, spending limits, and approval workflows, with every action recorded in an audit trail.
- Contextualize: Assess whether the vulnerable code is deployed, reachable, undefended, and linked to a potential breach path.
- Respond and verify: Apply compensating controls via WAF, EDR, IAM, or network policy, send the code fix to the appropriate engineering team, and retest the path to confirm resolution.
Most exposure-management tools stop after discovery and prioritization. The loop converts validated exposures into a governed security-operations workflow that applies immediate mitigations, routes permanent fixes, and verifies resolution.
Related: Open-Source Platform Enables Self-Improving AI Agents
A deployment in a global financial-services firm reduced 12.3 million raw findings to 0.46% requiring action and cut triage time from three weeks to 30 minutes.
Policy enforcement and audit trails
The control plane enforces enterprise-defined rules for model selection, repository access, data scope, retention, and approvals. It ensures source code and vulnerability data remain within authorized workflows and are never used to train third-party models. Every action—including what was scanned, by which model, and why—is logged in a complete audit trail.
Such control becomes essential as AI scanners generate findings at scale. Without it, security teams face overwhelming noise or risk exposing sensitive data to unintended models. The system’s connectors and data-scoping policies allow customers to specify which integrations access which data, reducing leaks or unauthorized use.
Exposure management has previously attempted to bridge the gap between discovery and response. Earlier tools relied on manual triage or static rule sets that couldn’t adapt to AI-generated findings. Tuskira’s method treats the entire lifecycle as a single, auditable workflow, a necessity as AI-driven attacks outpace traditional defenses.
CEO comments
“AI has industrialized vulnerability discovery,” said Piyush Sharma, Tuskira’s CEO. “The new bottleneck is determining which findings create real production risk and closing them before a patch ships. The Agentic Control Plane for Exposure Management governs how frontier models participate in enterprise security operations, validates reachability and defense coverage, and orchestrates response until closure is proven. Finding vulnerabilities is becoming commoditized. Closing the right exposure with proof is the product.”
The control plane is now available to all Tuskira customers as part of the platform’s core exposure-management capabilities.
