Criminal IP, the threat intelligence platform operated by AI SPERA, has introduced AITEM (AI-Powered Threat Exposure Management), a framework it describes as the next step beyond conventional Attack Surface Management (ASM). The announcement coincides with the company’s participation in GovWare 2026 in Singapore.

Traditional ASM tools focus on discovering internet-facing assets such as servers, domains, IP addresses, and admin panels before attackers find them. According to AI SPERA CEO Byungtak Kang, that kind of visibility is no longer sufficient on its own. Automated scanning, publicly available proof-of-concept exploit code, and AI-assisted vulnerability discovery have made it easier for threat actors to locate and target exposed assets, shifting the defender’s core challenge from visibility to speed of response.

What AITEM Adds

AITEM expands beyond external asset inventories to incorporate open-source intelligence, dark web data, internal infrastructure, Shadow AI, leaked data, and emerging vulnerabilities into a broader exposure management approach. Rather than stopping at discovery and generic risk scores, it aims to connect fragmented findings with context that helps security teams investigate, prioritize, and respond.

The framework applies AI across four stages:

  • Detect: Connect emerging threats and vulnerabilities to the products, services, and assets actually present in an organization’s environment.
  • Investigate: Let security teams query assets, exposures, and findings using natural language, consolidating relevant context in one place.
  • Prioritize: Evaluate exposure using organization-defined risk criteria alongside real-world exploitability and attacker activity, rather than relying solely on vendor risk scores.
  • Automate: Convert prioritized findings into alerts, tickets, and workflow actions routed to the appropriate teams.

AITEM is built on Criminal IP’s existing threat intelligence, which aggregates data on open ports, exposed services, vulnerabilities, connected infrastructure, abuse history, scanner activity, and malicious infrastructure.

Industry Context

Kang will present a case study on AI-driven ASM at GovWare 2026, framing the shift from asset discovery to threat hunting. The company positions AITEM within a broader industry trend toward integrated, AI-driven security operations, noting that agentic AI, AI SOC, and Shadow AI were prominent themes at RSAC 2026. Kang argued that competitive differentiation in ASM will increasingly hinge on speed of response and organizational mobilization rather than the sheer number of assets discovered, with AI handling repetitive analysis while humans retain judgment and accountability.