security

AI Agent Visibility Gap: Snyk's 2026 Numbers, Checked

August 6, 2026

AI Agent Visibility Gap: Snyk's 2026 Numbers, Checked

Snyk's Volume II research, published August 3, 2026, reports that a full AI estate is about three times what a model inventory shows, once frameworks, MCP servers, retrievers and datasets are counted. The "nearly doubled" adoption line is harder: it depends on a base Snyk does not publish.

TL;DR: During Black Hat USA 2026 week, Snyk released Volume II of its State of Agentic AI Adoption, built on more than 3,000 enterprise accounts and about 1.39 million code repositories.1 Two findings are strong and well-evidenced: the full AI component surface is roughly three times what a model inventory shows, and only 51% of model-deploying organizations declare any dataset in their repositories. The growth headline is shakier. Snyk says full-stack agentic adoption "has nearly doubled" in six months, but the percentages it published support anywhere from 1.39x to 1.83x depending on which base you use -- and Snyk publishes two different values for its own starting point. Meanwhile 25%, 28%, 33% and 46.9% are all circulating as agentic adoption figures, and an unrelated study publishes an identical 46.9% about something else entirely.

What You'll Learn

  • What Snyk's Volume II research actually reports, and on what data
  • Whether "full-stack agentic adoption nearly doubled" survives Snyk's own percentages
  • Why 25%, 28%, 33% and 46.9% are four different measurements, not four views of one
  • What "enterprises see only a third of their AI" does and does not mean
  • The data-lineage number that leaves the least room for argument
  • How the enterprise model mix shifted between January and May 2026
  • Which agent-discovery products launched during Black Hat USA 2026
  • The sampling caveat that changes how you should read every number here
  • A practical inventory checklist for teams already shipping agents

What Snyk actually published on August 3

Snyk released Volume II of its State of Agentic AI Adoption on August 3, 2026, from a Boston dateline, under the headline "Enterprises Are Blind to Two-Thirds of Their Own AI Attack Surface. The Blind Spot Is Growing Fast."1 The research draws on "more than 3,000 enterprise accounts worldwide." Help Net Security, writing on August 5, gives the precise figure as 3,044 enterprise environments across 1.39 million code repositories.2

The core observation is about composition rather than behaviour, which makes the AI agent visibility gap an inventory problem before it is a monitoring problem. Ask a security team what AI it runs and you get a list of models. Snyk's position is that the list is the smallest part of the estate:

Models are the visible tip. The composition is the iceberg.

-- Manoj Nair, Chief Technology and Innovation Officer, Snyk1

Around the models sit agent frameworks, MCP servers, retrieval systems, vector databases, datasets and supporting tools. Counting all of them, "the full AI surface is roughly three times what a model inventory shows, and the ratio held constant across every region Snyk measured."1 Snyk converts that ratio into the visibility claim in its headline -- if the model list is your inventory, you are looking at a third of the components. Whether the conversion is safe is a question worth its own section, and it gets one below.

Worth noting for calibration: the 3x ratio is not new to Volume II. Snyk's Volume I landing page from January 2026 already advertised "an AI footprint 3 times larger than model-only counts."3 The number that changed between volumes is the adoption figure, not the composition figure.

The methodology is unusually explicit for a vendor report, and worth reading before the percentages. Snyk states it used "anonymized and aggregated data sourced from organizations that use Snyk and successfully scanned an AI-BOM beginning May 2026," with Volume I comparison data drawn from its January 2026 report at n = 500+, and model capability scoring via the Epoch Capabilities Index, an external composite that stitches together scores from more than 50 benchmarks.14 Snyk describes the result as "the largest independent study of how enterprises are actually building with AI" -- its characterisation, and one worth holding lightly, for reasons in the sampling section below.

Did full-stack agentic adoption really double in six months?

It depends entirely on a base Snyk does not state, and the answer ranges from a clear no to a clear yes.

The press release's opening paragraph says "the share of organizations running full-stack agentic architecture has nearly doubled since Snyk's initial report from January 2026," and the page's meta description repeats "has nearly doubled."1 The same release supplies the underlying percentages: Volume I found 28% of organizations running agentic architecture, with 36% of those adopters running both agent frameworks and MCP servers together; Volume II puts agentic adoption at 33% overall, with the full-stack share among adopters at 50%.1

Snyk's sentence is about "the share of organizations," so the natural reading multiplies the two figures in each volume:

ReadingVolume IVolume IIChange
Full stack, share of all organizations (28% x 36% -> 33% x 50%)10.1%16.5%1.64x
Full stack, share of adopters only36%50%1.39x
Any agentic architecture, all organizations28%33%1.18x

A rise from 10.1% to 16.5% is a 64% increase, which is a steep curve for enterprise infrastructure. Whether 1.64x earns the word "doubled" is a judgment call about adjectives, not an arithmetic error -- but it is the most generous of the three rows above, and none of them reaches 2x.

Then there is the complication that undercuts the whole exercise. Snyk publishes two different values for its own Volume I starting point. The press release says 28%; the Volume I landing page says "1 in 4 organizations have already moved beyond prompt-based AI toward autonomous systems," which is 25%.13 Run the same multiplication on 25% and the picture changes: 0.25 x 0.36 = 9.0%, rising to 16.5%, or 1.83x. That is a near-doubling by any reasonable standard.

A third reading is available too. Help Net Security reports Volume II agentic adoption as 46.9% of AI-using organizations,2 while Volume I was drawn from organizations that had already run an AI discovery assessment.3 If both volumes are quoted on an AI-using base rather than an all-organizations base, the ratio climbs above 2x. The full report is gated behind a download form, so which base Snyk actually used for the headline is not checkable from outside.

So the honest verdict is narrower than "the claim is wrong." On the percentages in the press release, "nearly doubled" is a stretch. On the percentage on Snyk's own Volume I landing page, it is fair. Snyk does not say which pairing produced the headline, and it publishes both inputs.

The internal inconsistency is not confined to that one number, either. The italic subheading directly under the release's title says full-stack adoption "has increased significantly in just six months," and the quote from Anthony Larkin, vice president of product marketing, uses the same softer phrasing: "Full-stack agentic adoption increased significantly in the time it took most security teams to finish their last risk assessment."1 "Increased significantly" is defensible on every reading above. "Nearly doubled" survives in the opening paragraph and the meta description -- the two places a downstream writer is most likely to copy from. Not everyone did copy it: Help Net Security's write-up of the same report never uses doubling language at all.2

One more wrinkle for anyone quoting the interval. Snyk says "six months," measured report to report from January 2026. Its methodology dates the Volume II scan window to "beginning May 2026," which is four months after the January publication.1 The shorter interval would make the curve steeper, not flatter, so this one cuts in Snyk's favour.

Why 25%, 28%, 33% and 46.9% are four different measurements

The adoption percentage is where this story gets genuinely confusing, and the confusion is now propagating.

Four numbers are in circulation as "agentic adoption," and they are not interchangeable:

FigureWhat it measuresSource
25% ("1 in 4")Volume I, organizations past prompt-based AISnyk Volume I landing page3
28%Volume I, organizations running agentic architectureSnyk Volume II press release1
33%Volume II, "agentic architectures, now running in 33% of enterprises"Snyk Volume II landing page5
46.9%Volume II, share of AI-using organizations with agentic architecturesHelp Net Security2

The first two are the same finding at two levels of rounding, which is ordinary marketing practice and only becomes a problem when a growth headline is computed from one of them without saying which. The last two differ by denominator: 33% of everyone against 46.9% of the AI-using subset. If both come from the same dataset, the implied share of organizations using AI at all is 33 / 46.9, or about 70% -- a plausible number, and the reading that reconciles them.

Then there is the coincidence. On June 29, 2026, AvePoint published the third annual State of AI Report, conducted with Osterman Research across 750 enterprise leaders. One of its key findings: "46.9% of global employees utilize AI agents on a weekly or daily basis."6 Same number to one decimal place, different study, different unit -- employees rather than organizations, and reported by leaders about their staff rather than surveyed from staff directly. AvePoint's actual lead finding is a different one: the share of organizations that cannot tell whether employees use unsanctioned AI tools nearly tripled, from 6.3% in 2025 to 17.6% in 2026, and stands at 21.1% for AI agents specifically.6

Neither 46.9% is disputed in any source reviewed here. The point is narrower and more useful: that figure is now loose in the discourse attached to two unrelated measurements, and Snyk's own adoption percentages describe different populations at different dates on differently-sized samples. Any of them can be quoted accurately or catastrophically depending on whether the denominator travels with it. If you are putting one of these numbers in a board deck, carry the denominator, the date and the study name onto the slide.

What "seeing only a third" actually measures

This is the finding most likely to be over-read, so it is worth separating the two claims stacked inside the phrase "AI agent visibility gap."

The directly-evidenced claim is a composition ratio. Snyk's AI-BOM scans count AI components in code repositories. Models are one class; frameworks, MCP servers, retrieval systems, vector databases, datasets and supporting tools are the others. Across the sample, the total is about three times the model count, and Snyk reports the ratio was stable across every region measured.1 That is a clean, checkable measurement of what an AI estate is made of.

The stronger claim -- that security teams can see only a third of what runs -- is an inference from that ratio, resting on the premise that model inventories are what security teams actually maintain. Snyk's CTO makes the operational version explicitly:

Every security leader we talk to can tell us which models are approved. Almost none of them can tell us what's actually invoking those models, what data those systems can reach or what they're doing with the access they've been given.

-- Manoj Nair1

That is a claim about organizational practice, sourced to customer conversations rather than to the telemetry. It may well be right; it is a different kind of evidence from the 3x. An organization with a mature AI-BOM programme could have the same 3:1 component ratio and full visibility into all of it. The ratio describes the estate, not the observability of the estate.

The practical translation is still useful, and it does not depend on resolving that distinction: if your AI inventory is a list of approved models, it is describing roughly a third of the components in play. Everything an agent uses to reach data -- the framework, the MCP server, the retriever, the vector store -- sits outside it. That is the same enumeration problem that shows up in non-human identity and agent revocation, and the same one that makes containment and kill switches so hard to design after the fact. You cannot revoke or stop what was never on the list.

The lineage finding has the least interpretive slack

Of the figures Snyk chose to publish, one leaves the least room for argument, and it is not the one that got quoted. Among organizations with at least one deployed model, only 51% declare any dataset in their repositories.1 Snyk gives it a headline section of its own in the release -- "Half of model-deploying organizations can't trace their own data" -- so this is a promoted finding rather than a buried one; it simply lost the news cycle to the adoption percentage. Help Net Security's version reports that about half of organizations using AI models "could not be linked to the datasets used to train or fine-tune them."2

The qualifier matters and Snyk states it plainly: what is missing is a "visible, code-level link between a production model and the data that trained or fine-tuned it."1 Absence of a declared dataset in a repository is not proof that an organization cannot trace lineage at all -- the record may live in a model registry, a data catalogue or a vendor's documentation. But code-level declaration is what an automated scan can verify, and it is what an auditor can be shown quickly.

Snyk also reports this pattern "held steady across every region Snyk measured, including markets with more mature AI-specific regulation."1 That is the more interesting part. Regulatory maturity did not move the number, which suggests the gap is an engineering-practice problem rather than a compliance-pressure problem. Nair's framing: "Even the organizations doing this well can't answer where their model's behavior actually came from ... That's an audit, incident-response and compliance problem waiting to happen."1

For agent builders specifically, lineage is the difference between "the agent gave a bad answer" and "we know which corpus produced the bad answer." The supply chain makes it harder: Help Net Security reports 77.4% of AI packages and tools came from external sources against 22.6% built internally,2 and Snyk's release describes an AI estate "three-quarters of which come entirely from outside the organization."1

The model mix shifted underneath the agents

One number in the release has nothing to do with visibility and is worth pulling out on its own. Between the two reporting periods, Anthropic's share of enterprise model occurrences rose from 4% to 11%, while OpenAI's fell from 44% to 35%.1

Two cautions before anyone builds a narrative on that. These are shares of model occurrences in scanned repositories, not revenue, not workloads and not tokens; a single occurrence is a reference in code, and references are cheap. And the sample changed between volumes, from "500+" organizations to "more than 3,000" -- both figures are floors, so the expansion is somewhere around six-fold, and a change of that size can move a share figure on its own.

The surrounding composition data is steadier. Help Net Security reports the top four providers accounted for about 71% of identifiable model occurrences, with proprietary models at 63.8% of deployed models against 32.5% open source.2 The pattern described is proprietary models for reasoning and autonomous tasks, open models for embeddings and retrieval -- which is roughly what you would predict from cost-per-call economics, and a reasonable sanity check on the dataset. Also striking: nearly half the companies analyzed had no declared AI models in their repositories at all, using AI "through third-party services, packages and tools," while 17.2% ran large model fleets.2

Black Hat week turned agent discovery into a product category

Snyk's report did not land in isolation. Black Hat USA 2026 ran August 1-6 at Mandalay Bay in Las Vegas, a six-day programme with Trainings from August 1-4, a Summit Day on August 4 and a two-day main conference of Briefings closing the week.7 SecurityWeek's vendor round-up ran to at least three parts.8

Read the announcements against Snyk's thesis and a pattern shows up: discovery is the first verb in a striking number of them.

VendorAnnouncementWhat it enumerates
DrataAI Agent Governance, limited availabilityAgents running inside the organization; ships "first and deepest" for Anthropic9
Legit SecurityVibeGuard 2.0AI coding agents at the endpoint -- Claude Code, Cursor, GitHub Copilot -- plus MCP security controls8
SailPointSailPoint Identity SecurityHuman, non-human and agentic identities in one loop8
NetskopeOne DataSec Command CenterSensitive data across AI environments and the network8

Adjacent but not agent discovery: AvePoint's Kinetic Classification, announced the same day, continuously re-evaluates data sensitivity across Microsoft 365 and Google Workspace rather than inventorying agents.8 It belongs to the same governance wave, not the same product category.

Drata's is the closest fit to the gap Snyk describes. Its own August 4 release describes a product "designed to help enterprises discover, monitor, govern, and prove traceability of the AI agents running inside the organization," which "ships first and deepest for Anthropic, with early access customers already running it end-to-end in production."9 The architecture is worth noting because of where it sits: a device sensor, a telemetry layer, and an MCP proxy that "sits at the point every agent's tool call passes through and evaluates each request against policy."9 That is an explicit bet that the MCP boundary is the right chokepoint for agent governance.

Note what "limited availability" means here, though. This is not general availability; it is open to "qualified enterprises running agents on Anthropic," and Drata states that native coverage for OpenAI, Google Vertex AI and AWS Bedrock is "in active development."9 If your fleet is multi-provider, the product does not yet inventory most of it.

Discovery being the first verb also does not mean it is the only one. Drata explicitly positions against discovery-only tooling, arguing that "most tools available today stop at surface-level discovery" while its own policies are "enforced inline so a violating action is stopped before it executes."9 That is a competitive claim from a vendor about its competitors and should be read as one, but it is a fair warning against treating the table above as a list of dashboards.

Tanium's entry cuts the other way and is worth noting for balance -- its Atlas platform added an MCP server that exposes Tanium data to clients like Claude and Microsoft Security Copilot.8 The same week that vendors shipped tools to inventory MCP servers, at least one shipped a new MCP server. The surface these products measure is partly one the same industry keeps adding to.

The capital is moving too. On July 29, 2026, Onyx Security announced a $113 million Series B led by Bessemer Venture Partners, bringing its total to $153 million since founding two years earlier; SecurityWeek reports the round "reportedly" values the company at an estimated $640 million, linking to Calcalist for the figure, and notes Onyx did not officially disclose a valuation.10 Onyx's pitch is precisely the gap: finding shadow AI implementations and enforcing real-time safeguards. Its investor's framing is characteristically unhedged -- Cyberstarts general partner Hila Zigman called it "one of the defining security categories of the coming decade"10 -- which is what an investor in the company would say, and should be read as such.

The sampling caveat that shapes every number here

Every number above comes from one dataset with a specific shape, and the shape is stated in Snyk's own methodology: organizations that use Snyk and successfully scanned an AI-BOM beginning May 2026.1

That is a convenience sample twice over. These are security-tooling customers, and specifically the subset that adopted AI discovery scanning and completed a scan. Both filters select for organizations that are more AI-mature and more security-mature than a random enterprise. Whether that biases the adoption percentage up or down is genuinely unclear -- more AI-mature suggests higher agentic adoption, more security-mature suggests smaller visibility gaps -- but it means these are not population estimates.

The volume-over-volume comparison carries an extra caveat, and it is the one that makes the "nearly doubled" question unresolvable from outside. Volume I is n = 500+, drawn from early adopters of Snyk's Evo product; Volume II is 3,000+ accounts.13 Comparing percentages across two samples that differ roughly six-fold in size and, necessarily, in composition is a weaker operation than tracking the same cohort across two periods. That is not disqualifying -- telemetry has real advantages over surveys, since it measures what is in the repositories rather than what a respondent believes is in them. It does mean the six-month deltas deserve more hedging than they got.

One last disclosure, which Snyk makes itself rather than hiding: the release states that the expanding footprint, accelerating adoption and visibility gap "are the three loops Snyk built the Evo platform to close."1 The company measuring the problem sells the remedy. That is not a reason to dismiss the data -- it is a reason to read the framing and the measurements separately.

The downstream coverage shows why that matters. A Futurum Group analysis of the report repeated "nearly doubled" without checking it, and supported its governance argument with Futurum Research infographics dated January 2025 -- 19 months old at publication, with the vintage undisclosed in the body. That piece also carries an explicit notice that it "is written by a commercial general-purpose language model (LLM) ... and has not been curated or reviewed by editors."11 A vendor headline number can travel a long way before anyone runs the multiplication.

What to do if you are shipping agents

The practical takeaway does not depend on which adoption percentage is right.

  • Inventory component classes, not models. Enumerate agent frameworks, MCP servers, retrieval systems, vector databases and datasets as first-class entries. If your AI register has one column and it is model names, Snyk's 3x ratio says you are describing about a third of the estate.
  • Declare datasets in code. The 51% figure is a code-level measurement. A dataset reference sitting in a repository is the artifact an automated scan and an auditor can both consume; a lineage record in someone's notebook is neither.
  • Treat MCP servers as network egress, not configuration. An MCP server is what turns a model into something that reaches enterprise data. It belongs in the same review process as any other system with credentials and outbound access.
  • Write down the denominator. Whichever adoption statistic you cite internally, record which study, which date and which population. Half the confusion in this story is untracked denominators.
  • Ask where enforcement happens, not just whether it exists. Most of this month's launches do both discovery and enforcement, but at different points -- an endpoint sensor, an MCP proxy, an identity fabric. Discovery tells you what exists; the agent control plane question is who can stop this agent, at which chokepoint, right now.
  • Check the release stage, not the announcement. Drata's agent governance shipped as "limited availability" for Anthropic, with coverage for OpenAI, Google Vertex AI and AWS Bedrock still "in active development."9 Match a product's actual stage to how much of your control story depends on it.

Bottom line

The durable findings from Snyk's Volume II are the ones that need no interpretation: an AI estate is roughly three times the size of its model list, and about half of model-deploying organizations have no code-level record of what trained the models they run. Both are stable across every region Snyk measured, and both describe a real gap between what teams have written down and what is executing. The 3x is not even new -- Snyk published it in January and it did not move.

The growth headline is the soft spot, and not because anyone lied. "Full-stack agentic adoption has nearly doubled" resolves to 1.64x against the press release's own starting figure and 1.83x against the starting figure on Snyk's Volume I landing page. Both numbers come from Snyk; the release does not say which it used, and the full report is gated. That is an unforced ambiguity in a document whose entire subject is the cost of not knowing what your numbers refer to.

Which is the useful lesson here, and it generalises past this one report. The visibility problem Snyk is describing is real, and it starts one level earlier than the AI estate: with knowing what a number counts before repeating it. Checking took one multiplication.


Footnotes

  1. Snyk, "Enterprises Are Blind to Two-Thirds of Their Own AI Attack Surface. The Blind Spot Is Growing Fast.", press release, August 3, 2026. Date taken from the release's own Boston dateline. Contains the 28%/36%/33%/50% figures, the 51% dataset-declaration figure, the Anthropic and OpenAI share figures, the Nair and Larkin quotes, and the Methodology section. 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29

  2. Anamarija Pogorelec, "Your enterprise AI footprint is about three times bigger than your model list", Help Net Security, August 5, 2026. Source for 3,044 environments, the 46.9% of AI-using organizations figure, 71% top-four provider share, 63.8%/32.5% proprietary-versus-open split, 77.4%/22.6% external-versus-internal tooling split, and the 17.2% large-fleet figure. 2 3 4 5 6 7 8 9 10

  3. Snyk, "2026 State of Agentic AI Adoption", Volume I landing page. Subtitled "Anonymized Insights from 500+ Evo by Snyk AI Discovery Assessments," and notes the report "is based on anonymized AI-BOM data across a subset of pre-approved customers." This is the page that states the Volume I adoption figure as "Why 1 in 4 organizations have already moved beyond prompt-based AI toward autonomous systems" -- 25%, against the 28% given for the same finding in the Volume II press release. It also already advertised "an AI footprint 3 times larger than model-only counts" in January 2026. 2 3 4 5 6

  4. Epoch AI, Epoch Capabilities Index. A composite metric combining scores from more than 50 benchmarks onto a single capability scale, cited in Snyk's methodology for model capability scoring.

  5. Snyk, "2026 State of Agentic AI Adoption: Volume II", report landing page. States "3,000+ enterprise accounts and 1.39 million repositories" and "agentic architectures, now running in 33% of enterprises."

  6. AvePoint, "AvePoint Research Reveals AI Visibility Gaps Have Nearly Tripled as AI Agents Scale and Almost Half of Enterprise Employees Now Rely on Agents Daily or Weekly", GlobeNewswire, June 29, 2026. Third annual State of AI Report, conducted with Osterman Research; the study "surveyed 750 respondents with direct responsibility for information management, data security, or AI programs." Source for the 46.9%-of-employees figure and the 6.3% / 17.6% / 21.1% unsanctioned-tool visibility figures. 2 3

  7. Black Hat USA 2026, official event site. "Aug 1—6, Las Vegas," Mandalay Bay, six-day programme with Trainings August 1-4, Summit Day August 4, and two days of Briefings.

  8. SecurityWeek News, "Black Hat USA 2026 – Summary of Vendor Announcements (Part 2)", August 4, 2026. Source for the Drata, Legit Security VibeGuard 2.0, SailPoint, Netskope, AvePoint and Tanium entries. 2 3 4 5 6

  9. Drata, "Drata Extends Trust Management Platform to Continuously Monitor and Govern AI Agents", August 4, 2026. 2 3 4 5 6

  10. SecurityWeek News, "Onyx Security Raises $113 Million to Control AI Agents in the Enterprise", July 30, 2026, reporting an announcement made Wednesday, July 29. The $640 million valuation is reported as an estimate attributed to Calcalist and was not officially disclosed by the company. 2

  11. FuturumAI, "Are Enterprises Ignoring Two-Thirds of Their AI Security Risks?", Futurum Group, publication date stated on the page as August 6, 2026. Cited here only as an example of downstream repetition. The page carries an explicit notice that the content "is written by a commercial general-purpose language model (LLM)" and "has not been curated or reviewed by editors," and its governance statistics (56% with a governance council, 45% running regular audits) are sourced to Futurum Research infographics dated January 2025 -- 19 months before that publication date, with the vintage undisclosed in the body.

Frequently Asked Questions

Snyk's Volume II research reports that the full AI component surface is roughly three times what a model inventory shows, which it summarises as security programs seeing "roughly a third" of the real footprint. 1 The 3x is a measured component ratio; the "can only see a third" version additionally assumes model inventories are what teams maintain.