Firms unaware of most AI security risks

Enterprises are losing track of most of their own AI infrastructure. The gap between what security teams can see and what’s actually running is growing faster than they can close it.
A report from Snyk, an AI security company, found that security programs are only aware of about a third of their organization’s real AI footprint. The rest—agent frameworks, model control planes, retrieval systems, vector databases, and supporting tools—exists outside formal inventories, leaving most of the attack surface unmonitored.
Models are just the visible tip
When security teams inventory AI systems, they typically list models. That’s only a fraction of the full picture. The report surveyed more than 3,000 enterprise accounts worldwide and revealed the actual AI surface is roughly three times larger than what a model inventory shows.
Model adoption trends reflect this shift. Anthropic’s share of enterprise model usage rose to 11% in 2026, up from 4% earlier in the year, while OpenAI’s share dropped from 44% to 35%. Hugging Face and other open-source platforms are gaining ground, making the AI ecosystem more distributed and harder to track.
“Models are the visible tip,” said Manoj Nair, Snyk’s Chief Technology and Innovation Officer. “The composition is the iceberg. Every security leader we talk to can tell us which models are approved. Almost none of them can tell us what’s actually invoking those models, what data those systems can reach, or what they’re doing with the access they’ve been granted.”
Agentic AI adoption is accelerating faster than governance
Six months ago, 28% of organizations were running some form of agentic AI architecture. Today, that figure has climbed to 33%. Half of those adopters now run the full stack—agent frameworks, model control planes, and supporting infrastructure—up from 36% in January.
The speed of adoption is outpacing security teams. Anthony Larkin, Snyk’s vice president of product marketing, noted that technology shifts in security usually allow time to build governance alongside adoption. “This one doesn’t. Full-stack agentic adoption increased significantly in the time it took most security teams to finish their last risk assessment.”
Related: Benefits of VPS Hosting For eCommerce Websites
For many organizations, the shift from experimentation to full production happens in months. Once a company commits to agentic AI, it tends to adopt the full architecture quickly, leaving little room for incremental security adjustments.
Visibility isn’t the only issue. Half of organizations deploying AI models can’t trace the data used to train or fine-tune them. Only 51% of model-deploying enterprises declare any dataset in their repositories, meaning there’s often no code-level link between a production model and the data behind it. This gap persists even in regions with stricter AI regulations.
Most governance frameworks weren’t built for AI’s external, poorly documented supply chain. Nair explained that even well-prepared organizations struggle to answer where a model’s behavior originated. “That’s an audit, incident-response, and compliance problem waiting to happen.”
The industry is moving from experimentation to full production faster than the security tools designed to protect it. AI systems today form interconnected webs of agents, third-party tools, and data pipelines, most of which originate outside the organization. That makes them harder to track, secure, and govern.
Snyk’s findings show the problem will worsen as adoption grows. The company’s Evo platform addresses automated attacks that exploit blind spots, agentic development outside security oversight, and AI applications operating without governance.
The data reveals why these gaps are widening. For now, most enterprises are still trying to catch up.