Snyk has released its State of Agentic AI Adoption: Volume ll report, the largest independent study examining how enterprises are implementing AI. Based on data from more than 3,000 enterprise accounts worldwide, the research shows that most security teams have visibility into only about one-third of their organization’s actual AI usage, while adoption of full-stack agentic AI architectures has nearly doubled since Snyk’s January 2026 report.
AI models are the tip of the iceberg
Ask most security teams what AI they’re running and they’ll answer with a list of models, but that answer is missing two-thirds of the picture. In addition to LLMs, organizations are deploying agent frameworks, MCP servers, retrieval systems, vector databases, datasets and supporting tools. The full AI surface is roughly three times what a model inventory shows, and the ratio held constant across every region Snyk measured.
In confirmation that Anthropic has been steadily gaining traction in 2026, the Claude model maker’s share of enterprise model occurrences has risen to 11% from 4% while OpenAI’s share has fallen from 44% to 35%. Moreover, HuggingFace and the open ecosystem are taking real share, underscoring how the model market is becoming both more heterogeneous and distributed.
“Models are the visible tip. The composition is the iceberg,” said Manoj Nair, Chief Technology and Innovation Officer, Snyk. “Every security leader we talk to can tell us which models are approved. Almost none of them can tell us what’s actually invoking those models, what data those systems can reach or what they’re doing with the access they’ve been given. That’s not a knowledge gap at the edges; it’s the majority of the actual attack surface, sitting outside the inventory entirely.”
The shift is accelerating
The most urgent finding is the speed at which the gap is widening. Six months ago, Snyk’s first edition found that 28% of organizations were running agentic architecture, with 36% of those adopters running both agent frameworks and MCP servers together. Volume II shows agentic adoption climbing to 33% overall, and among adopters, the share running the full stack has jumped to 50%.
In practical terms, organizations that commit to agentic AI aren’t dabbling in a single layer anymore. Rather, more than half go all-in on the complete execution architecture within months of adopting it.
“We’ve watched a lot of technology shifts happen in security, and normally the adoption curve gives you time to build governance alongside it,” said Anthony Larkin, vice president of product marketing, Snyk. “This one doesn’t. Full-stack agentic adoption increased significantly in the time it took most security teams to finish their last risk assessment. The gap between what’s being deployed and what’s being governed is widening fast.”
Half of model-deploying organizations can’t trace their own data
The research surfaces a second consistent governance failure: among organizations with at least one deployed model, only 51% declare any dataset in their repositories. For roughly half of model-deploying organizations, there is no visible, code-level link between a production model and the data that trained or fine-tuned it. This pattern held steady across every region Snyk measured, including markets with more mature AI-specific regulation.
One major reason: The AI supply chain is heavily external, heavily concentrated at its core, and poorly documented at its lineage layer conditions that existing software governance frameworks were not built to handle.
“Even the organizations doing this well can’t answer where their model’s behavior actually came from,” said Nair. “That’s an audit, incident-response and compliance problem waiting to happen.”
What this means for security teams
Taken together, the findings describe an industry moving from experimentation to full production infrastructure faster than the governance layer built to secure it. AI comprises an interconnected system of agents, tools, data pipelines and third-party dependencies, three-quarters of which come entirely from outside the organization. Enterprises have never operated in a more porous environment than they do now.
The expanding footprint, accelerating full-stack adoption, and the ongoing visibility gap are the three loops Snyk built the Evo platform to close: automated attacks that exploit footprint faster than teams can see it, agentic development nobody’s watching and AI applications nobody’s governing. The State of Agentic AI Adoption: Volume ll Report includes the data behind why those three problems exist and why they’re accelerating.
The full report, “2026 State of Agentic AI Adoption: Volume II,” is available here.
Related News:
Minimus Open Source Program Launches for Hardened Images
2026 AI & Cybersecurity Trends Report Reveals AI Trust Gap by Arctic Wolf
Methodology
Anonymized and aggregated data sourced from organizations that use Snyk and successfully scanned an AI-BOM beginning May 2026, spanning approximately 1.39 million code repositories. Volume I comparison data is drawn from Snyk’s January 2026 report (n = 500+). Model capability scoring uses the Epoch Capabilities Index (ECI), an external benchmark from Epoch AI.