AI GovernanceJuly 21, 2026· 7 min read

ServiceNow's Third-Party AI Model Shift: Questions Every CIO Should Ask Before Enabling AI Agents

ServiceNow's July 9 update makes third-party models the default for Now Assist and moves voice toward action-based pricing. Here are the data, governance, and cost questions every CIO should answer before enabling AI agents.

Key takeaways

  • Starting July 9, 2026, third-party model providers become the default for out-of-the-box Now Assist skills and AI agents, rolling out with store app updates
  • New conversational AI agents let admins configure ITSM workflows in natural language, and voice services are moving toward action-based pricing
  • Buyers now need ongoing answers on which model processes their data, how routing changes affect compliance, and who governs AI-driven configuration changes
  • Action-based billing ties cost to AI activity, demand the action taxonomy and worked cost examples in writing before enabling

On July 9, 2026, ServiceNow began rolling out a quiet but consequential change to Now Assist: third-party model providers are becoming the default for out-of-the-box Now Assist skills and AI agents. The rollout is tied to individual store app release schedules, so different products switch at different times, but the direction is set. Alongside it, the July update introduces conversational AI agents that help administrators configure ITSM workflows in natural language, and voice services are moving toward action-based pricing, where individual AI actions during a call affect usage.

None of this is inherently bad. Using best-in-class external models is how most serious AI products are built today. But it does change the questions enterprise buyers need to ask: about data, about governance, and about cost predictability. This post covers what changed and the questions every CIO should have answered before enabling AI agents in ITSM.

What changed on July 9

Three things are moving at once:

  • Default model routing. Out-of-the-box Now Assist skills and AI agents where the default provider hasn't been changed will switch to a third-party model provider as store app updates are applied. Existing custom configurations are preserved, and admins can see assigned providers in the AI Control Tower or the Now Assist Admin Console. Customers in air-gapped, self-hosted, or regulated environments follow separate guidance.
  • Conversational configuration. New AI agents let administrators set up and adjust ITSM workflows using natural language rather than manual configuration: lowering the skill barrier, but also making it easier to change production behavior quickly.
  • Action-based voice pricing. Voice services are moving toward a model where individual AI actions taken during a call, not just the call itself, can affect usage. Combined with the assist-based consumption model already in the AI-native tiers, more of the bill now depends on what the AI does, not just who is licensed.

The questions that follow

1. Which model is processing our data, and do we know when that changes?

When the default provider can change with a store app update, "which model handles our tickets" stops being a one-time procurement answer and becomes an ongoing operational question. Ticket data routinely contains credentials, HR context, security incidents, and personal information. Your security and compliance teams will want to know: which providers are in the routing path today, what data-handling and residency terms apply to each, and what your notification and review process is when a default shifts. If your DPAs, vendor risk assessments, or regulatory attestations name specific processors, a silent default change is a compliance event, not just a technical one.

2. Does model routing change our security and compliance posture?

Third-party models can absolutely be deployed safely: the issue is visibility, not the vendor. What matters is whether you can see and control the routing: an inventory of which skills use which providers, the ability to pin or override defaults, audit trails of AI actions, and clear answers on training-data usage and retention. If those controls exist, use them. If you can't answer "which model touched this record" for an auditor, that gap is yours to close before agents go live.

3. Is action-based billing predictable?

Action-based pricing aligns cost with value in theory. In practice, it means your bill depends on how many actions your AI takes, and a well-adopted AI takes more actions every month. A single voice call might trigger a lookup, a summarization, a knowledge search, and a ticket update, each metering separately. Before enabling, ask for the full action taxonomy and per-action costs in writing, model your historical call and ticket volumes against it, and establish a consumption governance owner, the same discipline FinOps teams apply to cloud spend. If the vendor cannot give you a worked example of what last quarter would have cost under the new model, you cannot budget for next quarter.

4. Who is allowed to change what, and how is it governed?

Conversational configuration is genuinely useful, and it compresses the distance between "someone typed a sentence" and "production workflow changed." Approval gates, role-based permissions on AI-driven changes, and an audit trail of who instructed what become table stakes, not nice-to-haves.

How Rezolve.ai approaches the same problems

We build on the same reality, modern AI service desks use powerful models, but we treat transparency and governance as the product, not a console setting:

  • Glass-box by design. Sidekick answers with grounded, cited responses, and How Sidekick Thinks shows the eight specialized agents reasoning over one shared conversation, so you can see how an answer was produced, not just what it was.
  • Governed autonomy. Automation built in Agent Studio is approval-gated, audited, and explainable. Autonomy is always paired with control, whether an agent resets a password or executes a multi-step workflow.
  • Predictable economics. Rezolve.ai resolves roughly 70% of requests before they become tickets, and pricing is designed so success doesn't turn into a surprise invoice. See pricing for how that works.
  • Enterprise-grade posture. SOC 2 Type II, ISO 27001, GDPR, and HIPAA-ready, the credentials your risk team will ask about on day one. It's why organizations like JLL run programs on Rezolve.ai for roughly 100,000 employees across 80+ countries.

Bottom line

ServiceNow's July update is a rational engineering choice: route to the best available models, price AI by what it does, and let admins configure in plain language. The burden it creates is on the buyer: to know which models touch their data, to govern who can change what, and to forecast a bill that now moves with AI activity. Get those answers in writing before you enable, whatever platform you run.

If you want to see what a transparent, governed, predictably priced AI service desk looks like in practice, book a demo.

See the agentic service desk in action

Watch Rezolve.ai autonomously resolve real IT and HR tickets: governed, auditable, glass-box.

Book a demo
Saurabh Kumar
LinkedIn ↗

Get service-desk AI insights in your inbox

Practical guidance on agentic AI for IT and HR support: one email, no spam.

We use these details to respond to you. See our Privacy Policy.