What Changed
Tenable One AI Exposure now covers all four major LLMs in active enterprise use:
- Google Gemini (newly added)
- Anthropic Claude
- OpenAI ChatGPT Enterprise
- Microsoft Copilot
Beyond LLM coverage, the update extends discovery to Model Context Protocol (MCP) deployments and AI-native IDEs including Cursor, Windsurf, and Trae. AI-enabled browser extensions are also now in scope.
This matters because the attack surface for enterprise AI isn’t just the LLM itself. It’s the entire ecosystem of tools, integrations, and workflows built around it.
The Scale of the Problem
Tenable’s own data puts the risk in concrete terms. Across more than 7,000 organizations, the platform detected 457 million AI-related security issues over a 30-day period — averaging roughly 62,000 exposures per organization.
That’s not a theoretical risk. That’s an operational reality playing out right now, at scale, in environments where traditional security tools weren’t built to look.
The core issue is what Tenable calls the “AI exposure gap” — risk that emerges across interconnected applications, infrastructure, identities, and data, largely invisible to legacy security tooling.
Google Gemini Coverage
The Gemini integration includes monitoring of user interactions and prompt responses, policy enforcement, and detection of malicious activity and inappropriate usage. This brings Gemini in line with the governance controls already available for other major LLMs on the platform.
Expanded AI Visibility
Tenable One now doubles its coverage of both sanctioned and shadow AI. The addition of MCP deployments and AI-native IDEs is significant — these are exactly the kinds of tools developers are adopting quickly, often without formal security review.
Faster Remediation
Security teams can now create tickets directly in Jira and ServiceNow from within the platform. Policy violations can trigger automated notifications via email, Slack, or Microsoft Teams. This closes the loop between detection and action without requiring manual handoffs.
Two Distinct Capabilities Under One Platform
It’s worth understanding how Tenable structures this. Tenable One combines two separate but complementary functions:
- Tenable AI Exposure — discovers, assesses, and secures how AI is being used across the organization
- Tenable Hexa AI — the platform’s agentic engine, using AI to automate security tasks and accelerate remediation
In plain terms: AI Exposure helps you secure your use of AI. Hexa uses AI to make your security operations faster. They’re designed to work together as part of a preemptive security strategy rather than a reactive one.
Why This Update Is Worth Paying Attention To
Enterprise AI adoption is outpacing governance. That’s not a prediction — it’s already happening. Developers are spinning up AI-native IDEs, connecting MCP servers, and using browser extensions that touch sensitive data, often faster than security policies can catch up.
The risk isn’t just external attackers exploiting AI systems. It’s also unauthorized AI usage creating compliance exposure, data leakage, and attack paths that security teams can’t see with their current tooling.
Tenable’s positioning here is clear: unified visibility across all major LLMs and AI tools, in a single platform, with direct remediation workflows built in.
The Practical Takeaway
If your organization is running any combination of Gemini, Claude, ChatGPT Enterprise, or Copilot — and especially if developers are using AI-native IDEs or MCP-connected tools — the question isn’t whether you have AI exposure. It’s whether you can see it.
Platforms like Tenable One are increasingly relevant not because AI security is a new category, but because the scope of what needs to be secured has expanded well beyond what most teams initially planned for. Evaluating your current visibility gaps is a reasonable first step before that 62,000-exposure average becomes your organization’s headline.
Comments (0) No comments yet
Want to join this discussion? Login or Register.
No comments yet. Be the first to share your thoughts!