ArmorCode targets runaway AI costs with four new remediation agents

Exposure management startup ArmorCode Inc. today used Black Hat USA 2026 in Las Vegas to detail an expansion of its agentic artificial intelligence platform, adding four planned agents and three new sources of context aimed at narrowing what security teams remediate and capping what they spend doing it.

The additions extend the company’s Context Risk Graph, a data model that links security findings to asset inventory, ownership, business context, threat intelligence and remediation records. ArmorCode is feeding it network topology and reachability data, an integration with patch management systems and connections to compensating controls such as web application firewalls and endpoint detection and response tools.

The point of the three feeds is to let an agent establish whether a given flaw can actually be reached, whether a patch exists for it and whether a control the organization already owns is holding the line in the meantime. ArmorCode is also expanding its attack path analysis, which correlates findings with environmental context and renders the result as attack path visualizations.

“Finding vulnerabilities was never the hard part,” said Mark Lambert, chief product officer at ArmorCode. “What is challenging is that attackers can cheaply chain the findings teams deprioritized into real attack paths, while defenders find that AI without context is both wrong and expensive. The expanded ArmorCode Context Risk Graph gives AI the context to fix what actually matters and do it economically.”