As reported by BleepingComputer, Criminal IP by AI SPERA has unveiled AITEM (AI-Powered Threat Exposure Management), positioning it as the next evolutionary step beyond traditional Attack Surface Management. The announcement, timed ahead of GovWare 2026 in Singapore, reflects a shift the broader security industry has been circling for some time — and it deserves serious attention from defenders.

Key Insight: As reported by BleepingComputer, Criminal IP by AI SPERA has unveiled AITEM (AI-Powered Threat Exposure Management), positioning it as the next evolutionary step beyond traditional Attack Surface Management.

The ASM Ceiling Is Real

For years, ASM platforms have excelled at one thing: enumerating what you forgot you owned. Rogue subdomains, forgotten cloud instances, exposed admin panels, expired certificates on shadow infrastructure. That discovery work remains foundational. But the gap between knowing an asset exists and understanding whether it actually matters — whether it's exploitable, whether it's connected to something sensitive, whether an adversary is already probing it — has widened dramatically.

AI SPERA CEO Byungtak Kang's framing is accurate: visibility without action is a liability in itself. Security teams drowning in asset inventories without prioritization context are arguably worse off than teams with less complete visibility but sharper triage. Alert fatigue is not a perception problem — it's a structural failure of tooling that stops at enumeration.

Why This Shift Matters Now

The timing is not coincidental. Three converging pressures are forcing ASM vendors to evolve or face irrelevance:

The ASM Ceiling Is Real
AI-accelerated offensive tooling. Automated scanning, PoC generation, and AI-assisted vulnerability discovery have compressed the window between vulnerability disclosure and active exploitation. Defenders can no longer rely on weekly patch cadences.
Expanding exposure surfaces. Shadow IT was already unmanageable; now Shadow AI — unsanctioned LLM usage, AI APIs embedded in applications, and machine learning pipelines with exposed endpoints — has added another layer of unmonitored risk.
Convergence of intelligence streams. Dark web leak monitoring, OSINT correlation, and internal infrastructure telemetry were historically siloed. Threat exposure management requires all of them in one operational view.

The Industry-Wide Pivot

Criminal IP is not alone in this pivot. The move from ASM to Threat Exposure Management (TEM) — sometimes called Continuous Threat Exposure Management (CTEM), a framework Gartner has been promoting — is becoming the de facto direction for vendors who want to remain competitive. The differentiator will not be who has the most asset data, but who can best answer the question:

Of everything we've found, what should we fix first — and why?

That requires AI not as a buzzword, but as an operational layer that connects fragmented signals, enriches findings with business and threat context, and drives investigation workflows rather than generating more alerts.

What Shield53 Is Watching

The proof point for any TEM platform — AITEM included — is whether it genuinely reduces mean-time-to-remediation or simply shifts the alert burden to a different dashboard. We'll be watching for:

  • Integration depth with existing SOAR and ticketing workflows — does it drive action or just display it?
  • Quality of AI prioritization — is it contextualized to the organization's specific crown jewels, or generic CVSS-based scoring rebranded?
  • Coverage of Shadow AI and emerging exposure categories — many vendors claim this but deliver shallow detection.

Shield53 Recommendations

  • Audit your current ASM maturity. If your tooling produces asset lists but not prioritized remediation guidance, you're operating below the current threat curve. Identify the gap between discovery and action.
  • Define exposure SLAs by risk tier. Not every asset deserves the same response time. Map your crown jewels and enforce tighter remediation windows for exposures touching those assets.
  • Evaluate TEM platforms on workflow integration, not feature count. A platform that natively triggers remediation tickets, enriches with dark web exposure data, and correlates with internal telemetry will outperform a platform with more data but no orchestration.
  • Establish Shadow AI discovery processes now. Unsanctioned AI tooling is already in your environment. Whether you adopt a TEM platform or not, you need visibility into AI API usage, exposed model endpoints, and data flowing to third-party LLMs.
  • Benchmark against CTEM framework guidance. Gartner's Continuous Threat Exposure Management methodology provides a useful maturity model for evaluating whether your program — and any platform you consider — is genuinely moving beyond visibility.