NowSecure adds AI testing features for mobile app security teams
NowSecure says its new chat, MCP server and AI-specific detections are meant to help security teams assess mobile apps built with or using AI.
By Dominic Okoye · Staff Writer
· 3 min read
NowSecure has added AI-focused capabilities to its mobile application security testing platform, including a chat assistant, a Model Context Protocol server and detections for risks tied to AI-enabled apps. The company did not disclose pricing, revenue impact or adoption targets, but the release points to a practical issue for security teams: mobile apps are adding AI faster than review processes can account for it.
The update is aimed at enterprises that need to test mobile software across large app portfolios and feed those results into existing engineering workflows. NowSecure said the new features use data from binary analysis and runtime testing on real devices, rather than relying only on static app metadata or developer claims.
What NowSecure is adding
The new AI Chat feature lets security teams ask questions about their mobile apps in natural language. According to NowSecure, responses are based on the company’s testing data, including binary-level findings and runtime observations collected from devices.
NowSecure is also introducing an MCP server and expanding its application programming interface. The company said those pieces expose its mobile risk knowledge graph to external tools, including AI agents and DevSecOps pipelines. Engineering teams can use that access to pull in findings, test methods, remediation guidance, compliance mappings and supporting evidence.
The MCP positioning is familiar across enterprise software vendors this year: make proprietary data available to AI systems without forcing customers to abandon their internal tooling. NowSecure’s version is specific to mobile app security, where evidence trails matter for regulated buyers and where automated fixes can create their own approval problems. The company said the workflow is designed to automate more of the testing and remediation process while retaining human signoff where required.
NowSecure is also advancing AI Navigator, which it uses to crawl through apps and prioritize results. The company said the tool draws from internal technology as well as open-source projects including Frida and Radare2.
Why mobile AI risk is different
NowSecure is framing the release around the spread of AI inside mobile apps. In its 2026 Mobile App Risk Management Survey, the company said 95% of organizations reported using AI in mobile apps, while 37% said they lacked full visibility into AI behavior.
The company also said that, in its testing of 50,000 mobile apps, 53% included AI components. NowSecure claims many of those components are missed by conventional app review. The risk profile described by the company includes less visible data flows, changing identity and authorization patterns, and broader supply-chain exposure.
Those claims are directionally consistent with what security teams are seeing as mobile apps add AI features and connect to external model services. The harder part is operational: knowing whether an app is sending sensitive data to a third party, whether an AI feature changes access controls, and whether an app’s dependencies introduce model-related or agent-related behavior that was not present in older releases.
NowSecure also pointed to a next wave of AI agents that may act inside third-party apps, including booking travel, making purchases or accessing account data with less direct human input. The company did not provide customer deployment numbers for these scenarios.
The company is adding governance and policy controls, including more documentation and configuration options for regulated sectors such as banking, healthcare and government. NowSecure says its customers include the U.S. Departments of Justice, Defense and State.
NowSecure Chief Executive Alan Snyder said AI is changing both mobile development speed and app risk, and that testing needs to keep pace without removing people from final risk decisions. The company plans to demonstrate the features at Black Hat in Las Vegas next month.
This story draws on original reporting from SiliconANGLE.