News

Snyk Finds Agentic AI Stacks Outgrowing Model Inventories

Agentic AI architectures appeared in 33 percent of more than 3,000 enterprise accounts examined by Snyk, while the components surrounding AI models made the organizations' detected AI footprints approximately three times larger than model inventories alone indicated.

The findings come from Snyk's 2026 State of Agentic AI Adoption: Volume II, which examines how enterprises are assembling models, agents, Model Context Protocol (MCP) servers, tools, packages, datasets, retrieval systems and supporting frameworks. The results indicate that organizations adopting agentic systems are increasingly deploying both agent frameworks and the infrastructure that connects them to external tools and data.

The findings arrive amid agentic AI being in the limelight for another reason, as we've recently seen reports of agentic systems taking unintended actions, including a Claude model that continued offensive activity after being instructed to stop and OpenAI models that breached Hugging Face infrastructure while attempting to obtain answers during a cyber evaluation. Snyk did not examine such incidents, but its report maps the tools, data, services and permissions that determine what an agent can reach and do. "The governance unit is no longer the model response. It is the operational behavior of the system," the report stated.

Snyk based the report on anonymized and aggregated AI bill of materials (AI-BOM) data from 3,044 enterprise accounts and approximately 1.39 million code repositories. The accounts were located across the Americas, Europe, the Middle East and Africa, and the Asia-Pacific region. Snyk said the repositories were analyzed in June 2026, while its methodology covers organizations that successfully scanned an AI-BOM beginning in May.

The dataset represents organizations using Snyk and successfully completing an AI-BOM scan. It is not presented as a survey of all enterprises, and its findings concern AI components detectable through repositories and related telemetry.

Agentic Adoption Moves Toward Full Stacks
Of the 3,044 accounts examined, 1,004 showed evidence of an agent framework, an MCP server or both. That produced the overall agentic adoption rate of 33 percent, up from 28.4 percent in the first edition of the report, which was based on more than 500 environments.

Agentic Adoption
[Click on image for larger view.] Agentic Adoption (source: Snyk).

When the analysis was limited to the 2,142 accounts with any detected AI surface, agentic adoption reached 46.9 percent. Among the 1,004 agentic adopters, 262 used agent frameworks without detected MCP servers, 237 used MCP servers without detected agent frameworks and 505 used both.

That means 50.3 percent of agentic adopters had both layers, compared with 36 percent in the first report. Snyk described these deployments as execution systems that can retrieve information, invoke tools, coordinate workflows, access enterprise systems and perform actions rather than only generate content for people.

The report said this shift changes the unit that organizations must govern from an individual model response to the operational behavior of a larger system. It also identified MCP as increasingly common infrastructure for connecting agent logic with tools, services and data.

Models Account for One-Third of the Footprint
Snyk calculated an average of 0.080 models per repository when measuring AI use through models alone. The figure increased to 0.241 AI components per repository when frameworks, MCP servers, retrieval systems, vector databases, datasets and supporting tools were included.

The resulting three-to-one ratio was also observed in the report's regional comparisons. Density increased from 0.087 models to 0.281 total AI components per repository in the Americas and from 0.057 to 0.202 in Europe, the Middle East and Africa.

"Models are the visible tip. The composition is the iceberg," the report stated.

External dependencies represented most of this wider surface. Snyk detected approximately 164,000 packages and tools, of which about 127,000, or 77.4 percent, came from third-party packages. Approximately 37,000, or 22.6 percent, were custom-built tools. The resulting ratio was about 3.4 third-party components for each custom tool.

Data lineage was less consistently visible. Among 1,541 accounts with at least one detected model, 783, or 50.8 percent, declared any dataset in their repositories. Snyk calculated approximately 0.36 declared datasets for each model. The absence of a declared dataset means the scans did not identify a code-level link to training or fine-tuning data; it does not establish that no such information existed elsewhere.

Provider Mix Expands Beyond Two Vendors
The report identified more than 415,000 model occurrences and found changes in the provider distribution compared with its first edition. OpenAI remained the most frequently identified provider, but its share declined from 43.6 percent to 34 percent. Anthropic increased from 3.5 percent to 10.5 percent.

Provider Concentration
[Click on image for larger view.] Provider Concentration (percentage share of model occurrences) (source: Snyk).

The four largest providers still accounted for approximately 71 percent of identifiable model occurrences. Snyk characterized the results as a widening of the concentrated provider core rather than broad fragmentation.

Proprietary models accounted for 63.8 percent of detected model occurrences, compared with 32.5 percent for open source models. Models with unknown, non-commercial or research-only licensing made up the remainder. Proprietary models had represented 57 percent in the first report, although Snyk cautioned that some of the difference resulted from more detailed license classifications in Volume II.

Frontier-Adjacent Models Reach Production
Snyk also evaluated deployed model capabilities using the Epoch Capabilities Index (ECI) from Epoch AI. The report placed the April 2026 capability frontier at an ECI score of 160 and calculated a deployment-weighted average of 135.4 for proprietary models.

The report nevertheless found 1,874 occurrences of proprietary models scoring between 155 and 159, its frontier-adjacent category. The highest-scoring open source model observed in production received a score of 151.6. Snyk cited Epoch AI research indicating that open-weight models had trailed frontier closed models by approximately four months, or eight ECI points, since January 2026.

Snyk did not calculate a directly comparable weighted average for open source models because it described open source ECI coverage in the dataset as sparse.

The report's regional analysis found similar architectural patterns in the Americas and Europe, the Middle East and Africa, although the adoption rates and provider preferences differed. Agentic adoption reached approximately 36 percent in the Americas and 30 percent in Europe, the Middle East and Africa. Snyk said Asia-Pacific was represented in the overall dataset but did not provide an equivalent full regional comparison because the sample was not sufficient for that analysis.

In its announcement of the findings, Snyk said the combination of expanding component inventories, full-stack agent adoption, external dependencies and incomplete data lineage requires governance programs to account for complete AI systems rather than models in isolation.

About the Author

David Ramel is an editor and writer at Converge 360.

Featured

Subscribe on YouTube