SecurityBrief US - Technology news for CISOs & cybersecurity decision-makers
United States
Tanium adds autonomous AI security tools across platform

Tanium adds autonomous AI security tools across platform

Tue, 4th Aug 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Tanium has introduced new autonomous security features across its platform, covering agentic AI, exposure management and security operations.

The launch comes as security teams face faster, more complex attacks driven by artificial intelligence.

The new functions are intended to help operators detect, investigate and remediate threats while keeping automated actions under governance and audit controls. The rollout centres on Tanium Atlas, described as the operating layer for those processes.

Harman Kaur, Chief Technology Officer at Tanium, said the rise of AI agents is creating a new security challenge for large organisations as businesses rapidly deploy more software, cloud services and automated tools.

"At Black Hat USA 2026, vendors will be talking about AI agents and tools. What fewer will acknowledge is that ungoverned agents are themselves an emerging attack surface," said Kaur. "Tanium is the platform that governs and manages them with Tanium Atlas - where every action is auditable, boundaries are enforced, and everything is grounded in what's actually happening on the endpoint right now. What we are introducing at the conference extends that same principle across the full lifecycle from external exposure to detection to remediation."

Agentic AI

One part of the update focuses on how IT and security staff use AI tools in day-to-day operations. Atlas now supports what Tanium calls Agentic Performance Analysis, which traces the cause of a slow machine by analysing endpoint data instead of relying on manual checks across multiple logs and systems.

Tanium has also added Background AI Agents, designed to identify issues before an operator submits a query. These agents can carry out alert-to-resolution workflows within user-defined limits, with actions available for later review.

Another change expands Tanium Automate with endpoint-level sequence execution and a general API step. This allows workflows to run on individual endpoints while linking with external systems through REST and GraphQL interfaces.

Tanium also introduced Atlas MCP Server, which makes approved Tanium data and actions available inside AI clients that support the Model Context Protocol. This allows external AI tools such as Claude, Microsoft Security Copilot and Copilot Studio to interact with the platform under defined controls.

Exposure management

A second part of the announcement addresses internet-facing assets and the problem of fragmented visibility. Many organisations still lack a single view of hosts, services, certificates and web properties exposed online, making it harder to determine which issues present the greatest risk.

To address that, Tanium introduced an external attack surface management function that combines internet visibility from Censys with endpoint data gathered by Tanium. The aim is to give customers a continuously updated view of assets exposed to the internet alongside systems inside their environment.

It also launched Attack Path Mapping, designed to show how an attacker could move from an exposed internet asset into internal systems. The feature identifies the chain of access between an external weakness and sensitive systems so teams can prioritise fixes that close the most significant attack routes.

Tanium argued that exposure management is more useful when combined with live endpoint information because security teams can test whether an apparent weakness corresponds to actual activity or reachable systems, rather than relying on abstract risk scoring.

Security operations

The third area covers security operations and threat hunting. One of the main barriers to proactive hunting is the specialist time required to turn threat intelligence into a live investigation across an estate, Tanium said.

Its new Agent-Guided Threat Hunting feature lets an analyst describe a threat hypothesis in plain language, after which Atlas runs the search across endpoint data and maps findings to the MITRE ATT&CK framework. Tanium said this is intended to reduce the manual work involved in hunts that often depend on a limited pool of skilled personnel.

Tanium also announced an integration with Google Threat Intelligence in private preview. The integration combines intelligence from Mandiant, VirusTotal and Google with Tanium's endpoint visibility and control, which it said spans more than 36 million endpoints worldwide.

Google said the partnership is intended to shorten the gap between intelligence gathering and response. The integration is aimed at helping security teams determine whether an identified threat is active in their own environment and then take action across affected systems.

"Effective security operations require both high-fidelity intelligence and the ability to act on it instantly," said Miton Adhikari, Head of Google Security OEM Partnerships at Google. "By incorporating Google Threat Intelligence into Tanium's real-time visibility and control across endpoints, Tanium operators can validate signals against what's actually running in their environment and rapidly move from intel to remediation, at scale."