Commugen launches AI agents for third-party risk management

Jul. 7, 2026
By AI, Created 09:41 UTC, Jul 07, 2026, AGP -

Commugen on July 7 launched three AI agents meant to automate vendor security reviews, threat intelligence and external vulnerability scanning inside its Cyber GRC platform. The company says the tools are designed to cut manual work and help security teams keep up with growing third-party risk.

Why it matters: - Third-party risk management has become a core cybersecurity priority as organizations rely on more vendors, suppliers and cloud services. - Commugen’s new AI agents aim to reduce manual review work and give security teams faster, more consistent visibility into vendor risk. - The launch also reflects a broader shift toward AI-assisted Cyber GRC workflows instead of standalone chatbots.

What happened: - Commugen announced three AI agents on July 7, 2026, in London. - The new tools are built for Third-Party Risk Management and expand Commugen’s Cyber GRC platform. - The release includes an educational guide, “The CISO's Guide to Automating TPRM with AI.” - Commugen also pointed readers to its LinkedIn page.

The details: - The first tool, AI Evidence Analysis, reviews completed vendor questionnaires and supporting documents. - The agent checks ISO 27001 certificates, SOC reports, penetration test summaries, policies, business continuity plans and related evidence. - It flags missing documentation, expired certifications, weak responses and inconsistencies. - Commugen says AI Evidence Analysis can cut evidence review time by up to 70%. - The second tool, AI Cyber Threat Intelligence, takes a vendor name and searches public sources for cyber incidents, ransomware activity, breach disclosures, exposed credentials, security advisories and vulnerabilities. - The agent validates supplier identity and generates a report with references and an overall vendor cyber risk score. - The third tool, AI External Vulnerability Scanning, takes a vendor’s public domain and scans the external attack surface. - It identifies internet-facing assets, exposed services, known CVEs, outdated technologies, SSL/TLS weaknesses and misconfigurations. - The scanner produces a prioritized report with an overall vendor security risk score. - Commugen says the AI agents are intended to work inside existing security workflows and produce explainable results. - The company says customer information is never used to train AI models. - Commugen says organizations can deploy AI using private infrastructure when internal security or regulatory requirements call for it.

Between the lines: - The launch targets a common pain point in vendor risk programs: teams spend more time collecting and checking evidence than evaluating actual risk. - Commugen is betting that specialized agents will be easier to govern than a general-purpose assistant. - The focus on explainability, auditability and secure infrastructure suggests the company is positioning the product for regulated buyers. - The timing tracks with rising pressure from frameworks including NIS2, DORA, ISO 27001, SOC 2, NIST CSF and PCI DSS.

What's next: - Commugen says third-party risk management will keep moving toward continuous, AI-assisted monitoring rather than periodic questionnaires. - The company expects security teams to use AI more for evidence review, threat intelligence and external validation as vendor ecosystems grow. - Commugen is also building more specialized AI agents across the Cyber GRC lifecycle, including policy generation, mitigation planning, task generation and a GRC assistant.

The bottom line: - Commugen is pushing AI deeper into vendor risk operations, with the goal of speeding reviews, improving consistency and giving security teams a more current view of third-party exposure.

Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.

Sign up for:

Today in Education

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

Today in Education

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.