Home
News
Tech Grid
Interviews
Anecdotes
Think Stack
Press Releases
Articles
  • Agentic AI

Snyk Report: Enterprises Blind to Two-Thirds of AI Attack Surface


Snyk Report: Enterprises Blind to Two-Thirds of AI Attack Surface
  • by: Business Wire
  • |
  • August 4, 2026

Snyk, the AI security company, has released Volume II of its State of Agentic AI Adoption research, revealing that most security programs are only seeing roughly one-third of their organization's real AI footprint. The study, drawing on more than 3,000 enterprise accounts worldwide, also finds that the share of organizations running full-stack agentic architecture has nearly doubled since Snyk's initial report from January 2026.

Quick Intel

  • Security teams see only one-third of their organization's actual AI footprint; models are just the visible tip.

  • Full-stack agentic architecture adoption has nearly doubled from 28% to 33% in six months.

  • Among agentic adopters, the share running both agent frameworks and MCP servers jumped from 36% to 50%.

  • Claude's enterprise model share rose to 11% from 4%, while OpenAI's fell from 44% to 35%.

  • Only 51% of organizations with deployed models declare any dataset in their repositories.

  • The AI supply chain is heavily external, with three-quarters coming from outside the organization.

Models Are the Tip of the Iceberg

Ask most security teams what AI they are running and they will answer with a list of models, but that answer misses two-thirds of the picture. In addition to LLMs, organizations are deploying agent frameworks, MCP servers, retrieval systems, vector databases, datasets, and supporting tools. The full AI surface is roughly three times what a model inventory shows, and this ratio held constant across every region Snyk measured. The model market is becoming both more heterogeneous and distributed, with Anthropic's Claude gaining steady traction in 2026, rising to 11% of enterprise model occurrences from 4%, while OpenAI's share has fallen from 44% to 35%. HuggingFace and the open ecosystem are also taking real share, underscoring the shifting landscape.

The Shift Is Accelerating

The most urgent finding is the speed at which the visibility gap is widening. Six months ago, Snyk's first edition found that 28% of organizations were running agentic architecture, with 36% of those adopters running both agent frameworks and MCP servers together. Volume II shows agentic adoption climbing to 33% overall, and among adopters, the share running the full stack has jumped to 50%. Organizations that commit to agentic AI are no longer dabbling in a single layer; more than half go all-in on the complete execution architecture within months of adopting it. This rapid acceleration leaves security teams with little time to build governance alongside deployment.

Governance Failures and the Data Gap

The research surfaces a second consistent governance failure: among organizations with at least one deployed model, only 51% declare any dataset in their repositories. For roughly half of model-deploying organizations, there is no visible, code-level link between a production model and the data that trained or fine-tuned it. This pattern held steady across every region Snyk measured, including markets with more mature AI-specific regulation. One major reason is that the AI supply chain is heavily external, heavily concentrated at its core, and poorly documented at its lineage layer. Existing software governance frameworks were not built to handle these conditions.

What This Means for Security Teams

Taken together, the findings describe an industry moving from experimentation to full production infrastructure faster than the governance layer built to secure it. AI comprises an interconnected system of agents, tools, data pipelines, and third-party dependencies, three-quarters of which come entirely from outside the organization. The expanding footprint, accelerating full-stack adoption, and the ongoing visibility gap represent critical challenges. Snyk built its Evo platform to address these issues through automated attacks that exploit footprint faster than teams can see it, agentic development nobody is watching, and AI applications nobody is governing.

"Models are the visible tip. The composition is the iceberg," said Manoj Nair, Chief Technology and Innovation Officer, Snyk. "Every security leader we talk to can tell us which models are approved. Almost none of them can tell us what's actually invoking those models, what data those systems can reach or what they're doing with the access they've been given. That's not a knowledge gap at the edges; it's the majority of the actual attack surface, sitting outside the inventory entirely."

"We've watched a lot of technology shifts happen in security, and normally the adoption curve gives you time to build governance alongside it," said Anthony Larkin, vice president of product marketing, Snyk. "This one doesn't. Full-stack agentic adoption increased significantly in the time it took most security teams to finish their last risk assessment. The gap between what's being deployed and what's being governed is widening fast."

"Even the organizations doing this well can't answer where their model's behavior actually came from," said Nair. "That's an audit, incident-response and compliance problem waiting to happen."

About Snyk

Snyk, the AI security company, empowers the AI-driven enterprise to develop and secure its future, ensuring organizations can trust AI to innovate without limits. The Snyk AI Security Platform delivers the industry's AI Security Fabric, weaving protection directly into the flow of creation to secure GenAI code, AI-native applications, and agentic systems. By delivering visibility, control, and autonomous defense secure at inception, Snyk enables over 4,800 global customers to build fearlessly in the AI era.

  • Agentic AIAI SecurityCyber ResilienceAI Adoption
News Disclaimer
  • Share