Now Assist Secrets Revealed: What ServiceNow Partners Don't Want You to Know
I have witnessed firsthand how the ServiceNow partner ecosystem operates, and there is a troubling pattern I need to address. Too many ServiceNow consulting services providers are rushing clients into Now Assist implementations without full transparency about the platform's security risks and cost structures. After working with dozens of organizations navigating Now Assist deployments, I can no longer stay silent about what many partners conveniently omit from their sales presentations.
The truth is that Now Assist, while transformative, comes with critical considerations that demand strategic foresight and honest conversation. This guide will walk you through the hidden realities of Now Assist that every ServiceNow customer deserves to know before signing implementation contracts.
The Security Vulnerabilities No One Talks About
Let me be direct: ServiceNow recently patched a critical vulnerability (CVE-2025-12420) in Now Assist AI Agents and Virtual Agent API components that could allow unauthenticated users to impersonate other users. This isn't minor, this is fundamental platform security.
What concerns me more, however, is the second-order prompt injection vulnerability that security researchers discovered in the agent-to-agent discovery feature. I have seen implementations where this default configuration created a dangerous attack vector that most partners never mentioned during the sales cycle.

Here's how the attack works: low-privileged users can embed malicious instructions in data fields that higher-privileged AI agents later process. The compromised agent can then recruit more powerful agents to execute unauthorized actions, including accessing restricted records, modifying data, and potentially escalating user privileges. The most alarming aspect? These attacks succeeded even with ServiceNow's prompt injection protection features enabled.
When I audit Now Assist implementations, I consistently find that organizations were never informed about these configuration weaknesses enabled by default, including insecure LLM selection and default team-based agent grouping. The documentation initially lacked clarity about these security implications, leaving customers exposed without their knowledge.
The Licensing Cost Structure That Defies Budgeting
ServiceNow's consumption-based licensing model for Now Assist operates in a fog of opacity that makes long-term budgeting nearly impossible. I will guide you through the essential facts that many ServiceNow partners conveniently gloss over during contract negotiations.
ServiceNow does not disclose pricing for additional "assists" (units of usage) once customers exhaust their annual allotment. This ambiguity leaves organizations vulnerable to unexpected and escalating costs, particularly those operating on tight IT budgets. Based on my analysis of client usage patterns, Now Assist consumption grew 9X between January and June 2025, suggesting that consumption-based fees are rising at unprecedented rates.

Let me translate this into real business impact: organizations that budgeted $50,000 for Now Assist in 2025 are now facing mid-year conversations about additional expenditures they never anticipated. The lack of transparent unit pricing means you cannot model scenarios or build accurate TCO calculations. This is not how strategic technology investments should work.
I have personally witnessed C-suite executives blindsided by Now Assist overages six months into deployment because their ServiceNow implementation partner never provided consumption modeling or usage governance frameworks. This is unacceptable professional practice.
Configuration Defaults That Create Risk
The Now Assist platform ships with default configurations that prioritize ease-of-use over security hardening. While I appreciate ServiceNow's intent to reduce implementation friction, these defaults create exposure that demands immediate attention.
The agent-to-agent discovery feature is enabled by default, allowing AI agents to communicate across privilege boundaries. ServiceNow's engineering team confirmed these behaviors were intentional, but the security implications were not adequately communicated to customers during the initial rollout.

When I conduct Now Assist security assessments, I evaluate several critical configuration areas:
LLM Selection Policies: Default settings may allow agents to select language models that lack appropriate security controls for your data classification requirements.
Agent Grouping Architecture: Team-based agent grouping can inadvertently create privilege escalation pathways if not properly segmented according to your organizational structure.
Prompt Injection Controls: While ServiceNow offers protection features, they must be configured beyond default settings to address second-order injection attacks.
Authentication Boundaries: The CVE-2025-12420 vulnerability demonstrated that authentication controls require explicit hardening beyond out-of-box configuration.
What You Should Demand From Your ServiceNow Partner
Based on my experience conducting Now Assist implementations that prioritize security and cost transparency, here is what you should require from any ServiceNow consulting services provider:
Comprehensive Security Hardening Documentation: Your partner must provide detailed configuration hardening guides specific to Now Assist AI Agents, addressing the vulnerabilities I outlined above. Generic security checklists are insufficient.
Consumption Modeling and Governance Frameworks: Demand detailed consumption models based on your anticipated usage patterns, user counts, and use cases. Your partner should provide governance frameworks that include usage monitoring, threshold alerts, and cost containment strategies.
Transparent Licensing Guidance: Your partner should advocate on your behalf to ServiceNow for clear, documented pricing on overage units. If ServiceNow refuses to provide this transparency, your partner should help you negotiate caps or alternative pricing structures.
Security Assessment and Ongoing Monitoring: Initial security configuration is not enough. Require ongoing monitoring for emerging vulnerabilities and quarterly security posture reviews specific to your Now Assist implementation.

How SnowGeek Solutions Approaches Now Assist Differently
At SnowGeek Solutions, we have built our reputation on transparency and technical precision. When clients engage us for ServiceNow implementation projects involving Now Assist, we lead with honesty about both opportunities and risks.
I personally conduct security architecture reviews before any Now Assist deployment goes live. This includes configuration hardening beyond ServiceNow defaults, privilege boundary testing, and prompt injection attack simulation. We document every security control we implement and provide clients with ongoing monitoring protocols.
On the licensing front, we build detailed consumption models using historical data from similar implementations. We establish usage governance frameworks that include real-time monitoring dashboards, consumption alerts at 75% and 90% of allocated assists, and monthly cost reviews with recommendations for optimization.
Our clients never face surprise overage bills because we establish clear usage policies, train power users on consumption-conscious practices, and implement technical guardrails that prevent runaway usage before it impacts budgets.
The Path Forward: Transparency as Strategy
The ServiceNow ecosystem is at a crossroads. As AI capabilities like Now Assist become central to platform value, the partnership model must evolve beyond sales-driven implementation toward strategic advisorship grounded in transparency.
I have witnessed transformative outcomes when organizations approach Now Assist with eyes wide open: understanding both its capabilities and its complexities. The platform can deliver unprecedented operational efficiency, but only when implemented with appropriate security controls and cost governance.
The secrets I have revealed in this guide should not be secrets at all. They should be standard components of every Now Assist conversation between partners and clients. The fact that they are not tells you everything you need to know about the current state of the ServiceNow partner ecosystem.

Take Control of Your Now Assist Journey
You deserve a ServiceNow partner who prioritizes your long-term success over short-term contract values. You deserve transparent conversations about security, realistic consumption modeling, and ongoing governance support that protects your investment.
If you are evaluating Now Assist or concerned about your current implementation, I invite you to visit the SnowGeek Solutions contact page to share your project details. Let's have an honest conversation about your requirements, risks, and opportunities.
Additionally, register with SnowGeek Solutions for platform updates and expert insights. We publish detailed technical analyses of ServiceNow releases, security bulletins, and implementation best practices that help you stay ahead of issues before they impact your organization.
The Now Assist platform represents the future of ServiceNow's AI capabilities. Approach it strategically, demand transparency from your partners, and never accept vague answers about security or costs. Your organization's operational excellence demands nothing less.

Comments