Azul has launched an AI Assistant for its Intelligence Cloud platform that enables IT, DevOps and security teams to query live Java runtime data in plain language to pinpoint unpatched versions, unlicensed JVMs and unused code before they trigger incidents or audit findings.
The tool, announced on 24 September 2026, sits atop Azul’s continuously updated JVM Inventory and Code Inventory, replacing static reports that become outdated as Java Virtual Machines spin up, patch and drift in production.
The move comes as the threat landscape accelerates. Anthropic’s Mythos model and OpenAI’s Aardvark agent have demonstrated the ability to autonomously discover and exploit previously unknown vulnerabilities, while the UK’s National Cyber Security Centre assesses that AI-enabled intrusion capabilities will spread to a wider range of state and non-state actors by 2027.
With the window between CVE disclosure and weaponisation already compressed to under five days against a median 32-day patch cycle, “that used to be a productivity problem. Now that AI can find and weaponize a vulnerability in hours instead of weeks, it’s a business risk — for security, for compliance and for the licensing exposure that shows up in an audit,” said Scott Sellers, co-founder and chief executive of Azul.
Azul identifies three compounding exposures as Java estates grow: commercial licensing risk from unlicensed or unsupported JVMs running unnoticed; security risk from unpatched, vulnerable Java versions still in production; and maintenance overhead from unused and dead code that continues to be tuned and migrated because teams cannot safely assess what can be removed.
The AI Assistant allows users to ask questions such as “Which JVMs are running Java versions which are not the latest updates?”, “Where is Oracle Java running in production right now?” and “What code hasn’t run in the past four quarters and is safe to remove?”, with answers grounded in live production data rather than point-in-time scans.
Because the assistant answers in plain language, the same runtime data becomes directly usable by non-technical decision-makers. A compliance officer preparing for an audit, a CFO weighing Oracle licensing exposure ahead of a renewal, or a CISO reporting current risk to the board can obtain defensible answers without waiting for a technical team to pull and interpret data first.
For managed service providers and systems integrators, the assistant provides an on-demand deliverable they can offer as part of ongoing managed services.
The assistant does not take action in customer environments; it only answers questions against JVM Inventory and Code Inventory’s runtime data drawn from live production, with no added performance overhead. It works across JVMs from any vendor and retains historical component and code-use records, enabling queries about what ran previously as well as what is running now.
“The Azul Intelligence Cloud AI Assistant lets IT and security teams ask a direct question, in plain language, and get an answer grounded in what’s actually running in production right now, as well as query historical information for further analysis,” Sellers said.











