Press Releases
>
ONEKEY AI Agent Brings AI to Firmware Security

ONEKEY AI Agent Brings AI to Firmware Security

ONEKEY AI Agent Brings AI to Firmware Security
Tanja Sommer
Tanja Sommer
TablE of contents

READY TO UPGRADE YOUR RISK MANAGEMENT?

Make cybersecurity and compliance efficient and effective with ONEKEY.

See it in Action
New AI capability of the ONEKEY platform makes complex security information accessible via natural language

Düsseldorf, September 1, 2026 – Artificial intelligence is fundamentally reshaping cybersecurity. ONEKEY, a product cybersecurity specialist, headquartered in Düsseldorf, is embracing state-of-the-art large language models (LLMs) by introducing the new ONEKEY AI Agent. However, the AI is uniquely enriched with analysis results generated by the ONEKEY Platform. Users can query security information and firmware analysis results in natural language and receive answers based on the platform's actual findings. Developed entirely by ONEKEY, this technology significantly improves the accuracy, transparency, and traceability of AI-generated responses.

"The goal in product cybersecurity isn't to generate answers that merely sound convincing. What matters is technical accuracy and reliability," said Jan Wendenburg, CEO of ONEKEY. "The ONEKEY AI Agent combines the power of modern AI with the deep analysis capabilities of our platform. Every response is grounded in verifiable security data." The AI operates directly on the platform's analysis results, including firmware extraction, binary inspection, Software Bills of Materials (SBOMs), component analysis, and vulnerability intelligence.

The new functionality is fully integrated into the ONEKEY platform. Following the current beta program, the initial release will be available in September and will continuously expand. The goal is to help security teams move more quickly transform to highly complex firmware data into actionable insights and informed decisions.

Deterministic AI Instead of Generic Responses

Generative AI has demonstrated the power of natural language interfaces. However, professional security environments require a higher standard: Responses must be transparent, verifiable, and based on concrete technical evidence.

"The market is currently focused on AI copilots, chatbots, and agentic AI. However, in cybersecurity, simply layering a language model on top of existing workflows is not enough," Wendenburg explained. "With the ONEKEY AI Agent, we've deliberately adopted an 'evidence first' rather than an 'AI first' approach. What matters isn't whether AI can generate a plausible answer—it is whether every answer is backed by verifiable technical facts." He continued: "Our AI Agent does not generate assumptions or generic responses from a general-purpose AI model. Every answer is based on the ONEKEY Platform's actual findings — from firmware extraction and binary inspection to SBOM detection, component analysis, vulnerability intelligence, and impact context. The result is responses that are transparent, contextual, and technically reliable."

"The second key differentiator is contextual awareness," Wendenburg added. "The ONEKEY AI Agent automatically recognizes whether a user is analyzing firmware, reviewing an SBOM, or assessing vulnerabilities. It understands the user's workflow and provides assistance exactly where security teams need it most."

Firmware Security Through Natural Language

The ONEKEY AI Agent does not replace technical security analysis—it makes the results faster and easier to access. Complex data becomes easier to understand, relationships become clearer, and decision-making process becomes more efficient.

Users can retrieve security insights by simply asking questions in natural language. The AI will automatically recognize the user's current context within the platform—whether it be firmware analysis, SBOM management, or vulnerability management—and deliver answers tailored to that specific task.

Security teams, for example, can inquire about vulnerabilities, CVEs, severity levels, exploitability, and recommended mitigation measures. They can also investigate software components, versions, component-specific vulnerabilities, affected products, and software dependencies eliminating the need for manual searches through technical data. In addition, users can evaluate the relevance of specific vulnerabilities to their own firmware.

"Many organizations don't suffer from a lack of security information," Wendenburg said. "Their challenge is making the right information available at the right time. AI can deliver a significant productivity boost in this area."

From Expert Knowledge to Intelligent Assistance

Another key capability of the AI-powered assistant is its support of the ONEKEY Query Language (OQL). OQL enables highly detailed analysis within the platform. The ONEKEY AI Agent can generate OQL queries from natural language, explain existing queries, and help optimize them.

This makes advanced analysis capabilities accessible to a much broader group of users. Security professionals can now spend less time operating technical tools and more time evaluating risks and implementing security improvements.

The ONEKEY AI Agent also provides contextual assistance directly within users' workflows. Questions about using the platform can be answered immediately without searching documentation or opening support tickets.

AI That Fits Each Customer's Security Strategy

Because organizations have different data privacy, compliance, and infrastructure requirements, ONEKEY takes a flexible approach to AI deployment. Customers will be able to use the provided and approved ONEKEY AI models or integrate their own models and API keys based on their internal security requirements.

The platform supports the Bring Your Own Model (BYOM) and Bring Your Own Key (BYOK) approaches. These approaches allow organizations to tailor their AI deployments to their specific business, industry, and regulatory requirements.

"The real breakthrough comes when AI connects expert knowledge with trusted analysis results and real product data," Wendenburg concluded.

First Step in a Four-Stage AI Roadmap

The new ONEKEY AI Agent represents the first milestone in ONEKEY's four-stage AI roadmap. The company's vision is to transform the ONEKEY security platform into a comprehensive product security assistant that complements, rather than replaces, human decision-making.

In the second phase, organizations will be able to securely connect their AI agents, applications, and automated workflows to the platform. The third phase will see the AI evolve from an information system into an intelligent security assistant. The fourth stage will support complete product security workflows. Over time, the platform will assist with a broad range of operational product security tasks while maintaining full transparency and traceability.

"Our AI roadmap demonstrates how Decision Intelligence becomes reality step by step—as a trusted assistant for those who make security-critical decisions every day," said Wendenburg.

Share

About Onekey

ONEKEY is the leading European specialist in Product Cybersecurity & Compliance Management and part of the investment portfolio of PricewaterhouseCoopers Germany (PwC). The unique combination of the automated ONEKEY Product Cybersecurity & Compliance Platform (OCP) with expert knowledge and consulting services provides fast and comprehensive analysis, support, and management to improve product cybersecurity and compliance from product purchasing, design, development, production to end-of-life.

CONTACT:
Sara Fortmann

Senior Marketing Manager
sara.fortmann@onekey.com

euromarcom public relations GmbH
team@euromarcom.de

Make cybersecurity and compliance efficient and effective with ONEKEY.