Most companies deploying AI have no clear picture of how much of it they are running. That is the headline finding of a new report from the security firm Snyk, its second study this year on how businesses are adopting so-called agentic AI. Drawing on more than 3,000 enterprise accounts, the study concludes that a typical security program sees only about a third of its organisation's real AI footprint.
The gap comes from where teams are looking. Security staff tend to inventory the models, the visible, brand-name systems bought and approved through official channels. But a working AI deployment is much more than a model. It includes agent frameworks, the connectors and MCP servers that let agents reach other software, retrieval systems, vector databases, datasets and a long tail of supporting tools. Count all of that, Snyk says, and the true surface is roughly three times what a model inventory shows.
Shadow AI grows up
"Shadow IT" has been a security headache for years, the apps and services employees adopt without telling anyone. Shadow AI is the same problem with sharper teeth. When an employee wires up an autonomous agent to company data using tools nobody vetted, the risk is not just an unpatched app. It is a piece of software that can act on its own, make decisions, and reach across systems.
That is what makes the blind spot dangerous rather than merely untidy. A compromised agent does not sit still. It can chain together small weaknesses that would each be low priority on their own, and it can do so at machine speed, without a human in the loop. Snyk also reports that the share of organisations running a full agentic stack has nearly doubled since its January survey, so the unmanaged surface is expanding while defenders are still mapping the old one.
The uncomfortable part
None of this means companies should stop adopting AI, and Snyk, which sells tools to secure it, has an obvious interest in the alarm. But the underlying tension is real and hard to wish away. The pressure to ship AI features quickly runs directly against the slower work of governing them, and right now shipping is winning.
The fix is not exotic. It starts with discovery, actually finding the agents, connectors and data flows already in use, before trying to secure them. You cannot protect what you cannot see. That defensive posture is the flip side of the offensive AI security work we wrote about recently, when Microsoft turned AI agents loose on defending its own networks. Both point at the same near future, one where much of the security fight, on attack and defence alike, is carried out by software acting largely on its own.
Sources
- i. www.itpro.com
- ii. snyk.io
- iii. futurumgroup.com
- iv. www.01net.it
Commentarii · 0