On July 23, 2026, Chicago‑based mobile security firm NowSecure announced a new set of artificial‑intelligence‑native features for its testing platform. The update introduces a chat assistant, a Model Context Protocol (MCP) server, and enhanced detection tools that focus on vulnerabilities in mobile apps that embed AI components.

The company said the changes are designed to keep pace with the rapid adoption of AI in mobile applications. According to NowSecure’s 2026 Mobile App Risk Management Survey, 95 % of surveyed organizations already run AI inside their mobile apps, but 37 % reported that they cannot fully see what that AI is doing. The new AI Chat lets security teams ask plain‑language questions about their app portfolio; the answers are generated from binary analysis and runtime data collected from real devices.

The MCP server and an expanded application programming interface (API) open NowSecure’s mobile risk knowledge graph to external software. Engineering teams can feed findings, testing methods, remediation guidance, compliance mappings, and supporting evidence into their own AI agents and DevSecOps pipelines. NowSecure said the setup allows teams to automate testing and fixes while maintaining the human approval steps required in regulated environments.

In addition to the chat and MCP additions, NowSecure is advancing its AI Navigator tool, which automatically explores apps and triages results. The platform uses internal tooling and open‑source projects such as Frida and Radare2. The company said the Navigator now includes detection aimed at AI itself. In a scan of 50,000 mobile apps, NowSecure found that 53 % contain AI components, many of which slip past conventional app review. The presence of AI introduces new exposure vectors: data flows become opaque, identity and authorization models shift, and supply‑chain risk widens.

NowSecure said the exposure is expected to grow with the arrival of AI agents that can book travel, make purchases, and access account data inside third‑party apps without a person driving each step. To address these risks, the company is expanding governance and policy controls, adding documentation and configuration options for regulated buyers in banking, healthcare, and government. NowSecure counts the U.S. Departments of Justice, Defense, and State among its customers.

Alan Snyder, NowSecure’s chief executive, said AI is “reshaping both mobile development speed and app risk,” and that risk management must evolve accordingly. He framed the update as a way to automate testing without sacrificing the visibility teams need to make sound risk decisions. Snyder added that the tools let teams automate more of their testing, but risk decisions still route through people.

The company will demonstrate the new features at Black Hat in Las Vegas next month.

The announcement comes as mobile app security firms continue to adapt to the growing integration of AI in consumer and enterprise applications. By providing AI‑native testing tools that integrate with existing security workflows, NowSecure aims to give security teams a clearer view of how AI components behave and how they might introduce new vulnerabilities.

The update also highlights the broader industry trend of embedding AI into security tooling. The Model Context Protocol, an open standard that allows large language models to securely access tools and data sources, is being adopted by several security vendors. NowSecure’s MCP server is one of the first implementations that connects a security knowledge graph to external AI agents.

In summary, NowSecure’s new AI‑native testing suite expands the company’s ability to detect AI‑specific vulnerabilities, automate testing workflows, and provide governance controls for regulated sectors. The company will showcase the features at Black Hat, and the industry will likely watch how these tools influence mobile app security practices in the coming months.