Are Enterprises Ignoring Two-Thirds of Their AI Security Risks?

Agentic AI

Snyk's latest research reveals that enterprises can identify only roughly one-third of their actual AI footprint, leaving two-thirds of the AI attack surface invisible to security teams [1]. Full-stack agentic AI architectures have nearly doubled in adoption over just six months, while governance structures lag dangerously behind [1]. In a cybersecurity market forecast to grow from approximately $195B in 2024 to $338B in 2029 at an 11.6% CAGR [2], Snyk's Evo platform is positioned to capture urgent enterprise demand for AI visibility and control [1].

What is Covered in this Article

  • The expanding AI attack surface blind spot [1][1]
  • Systemic governance gaps across enterprise AI programs [3][4]
  • Cybersecurity market growth and Snyk's Evo platform opportunity [2][1]

The News: Snyk's 2026 State of Agentic AI Adoption report exposes a critical enterprise security gap: organizations are aware of only approximately one-third of their actual AI attack surface, leaving two-thirds invisible to security teams [1]. Adoption of full-stack agentic AI architectures has nearly doubled in just six months, with deployment speed consistently outpacing security and governance framework development [1]. Security teams can identify AI models in use but lack visibility into the broader ecosystem, including frameworks, servers, and datasets supporting those models [1]. Many organizations also cannot trace the data linked to their deployed AI models, creating serious compliance and incident-response challenges [1]. To address this growing gap, Snyk has developed the Evo platform, specifically designed to close AI visibility deficits and strengthen governance over AI applications [1].

Enterprises Are Blind to Two-Thirds of Their AI Attack Surface

Analyst Take: Snyk's findings land at a moment when the pace of agentic AI adoption has structurally outrun enterprise security readiness [1]. The two-thirds visibility gap is not a temporary lag, it reflects a fundamental mismatch between how fast organizations are deploying AI and how slowly governance infrastructure is being built [1][3]. Until that gap closes, every new AI workload added to the enterprise stack expands an attack surface that security teams cannot fully see.

An Invisible Attack Surface That Keeps Growing

The scale of the blind spot is striking. Enterprises can identify only roughly one-third of their actual AI footprint, meaning the majority of deployed models, frameworks, servers, and datasets operate outside security team visibility [1][1]. This is not a static problem. Full-stack agentic AI architectures have nearly doubled in adoption over six months, compressing the window organizations have to establish baseline visibility before the surface expands further [1]. The challenge is compounded by an increasingly heterogeneous AI market, where emerging players are gaining market share alongside established vendors, multiplying the number of components security teams must track [1]. Organizations that cannot trace the data linked to their deployed models face compounding risk: limited incident-response capability and growing compliance exposure [1]. The attack surface is not just large, it is accelerating.

Governance Gaps Are Structural, Not Incidental

The visibility problem has a governance root cause. According to the Futurum Group CEO AI Readiness Study, only 56% of organizations have a dedicated AI governance council [3], meaning nearly half of enterprises lack the organizational structure needed to own AI security accountability. The audit picture is worse: just 45% of organizations conduct regular audits and assessments of their AI programs [4], leaving the majority without a systematic mechanism to detect drift, new deployments, or emerging risks. A meaningful 10% of enterprises have taken no formal AI governance steps at all [4]. These figures confirm that the visibility gap Snyk documents is not an anomaly, it is the predictable output of governance frameworks that were never built to match the speed of AI adoption [1]. Closing the blind spot requires both technical tooling and organizational commitment.

Market Tailwinds and the Evo Platform Opportunity

The urgency of the AI security problem coincides with a cybersecurity market in sustained expansion. The market is forecast to grow from approximately $195B in 2024 to $338B in 2029 at an 11.6% CAGR [2], driven in part by exactly the kind of novel, fast-moving threat surface that agentic AI creates. Snyk's Evo platform is purpose-built for this environment, targeting the AI visibility and governance deficit that its own research quantifies [1]. The heterogeneous and rapidly evolving AI market creates durable demand: as new models, frameworks, and agentic architectures enter enterprise environments, the need for continuous discovery and control does not diminish [1]. Snyk's positioning, combining developer-centric security heritage with AI-specific visibility tooling, gives it a credible entry point into a segment where few vendors have built dedicated solutions at scale.

What to Watch

  • Evo platform adoption: which enterprise segments deploy first and at what velocity over Q4 2026 [1]
  • Governance framework maturation: whether the share of organizations with dedicated AI governance councils rises meaningfully above 56% in the next two quarters [3]
  • Audit adoption rate: whether regular AI audits and assessments expand beyond the current 45% baseline as regulatory pressure increases [4]
  • Competitive response: how rival security vendors reposition or build out AI attack surface visibility capabilities through Q1 2027 [1]
  • Agentic AI proliferation pace: whether full-stack agentic architecture adoption continues its near-doubling trajectory and further widens the visibility gap [1]

Sources

1. Enterprises Are Blind to Two-Thirds of Their Own AI Attack Surface. The Blind Spot Is Growing Fast., Snyk, August 2026

2. 1H 2026 Cybersecurity Market Sizing & Five-Year Forecast, Futurum Research, June 2026

3. CEO Governance Infographic, Futurum Research, January 2025

4. CEO Responsibility Infographic, Futurum Research, January 2025


Declaration of generative AI and AI-assisted technologies in the writing process: This content has been generated with the support of artificial intelligence technologies. Due to the fast pace of content creation and the continuous evolution of data and information, The Futurum Group and its analysts strive to ensure the accuracy and factual integrity of the information presented. However, the opinions and interpretations expressed in this content reflect those of the individual author/analyst. The Futurum Group makes no guarantees regarding the completeness, accuracy, or reliability of any information contained herein. Readers are encouraged to verify facts independently and consult relevant sources for further clarification.

Disclosure: Futurum is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.

Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of Futurum as a whole.

Read the full Futurum Group Disclosure.

Author Information

FuturumAI

This content is written by a commercial general-purpose language model (LLM) along with the Futurum Intelligence Platform, and has not been curated or reviewed by editors. Due to the inherent limitations in using AI tools, please consider the probability of error. The accuracy, completeness, or timeliness of this content cannot be guaranteed. It is generated on the date indicated at the top of the page, based on the content available, and it may be automatically updated as new content becomes available. The content does not consider any other information or perform any independent analysis.

Related Insights
Why AI Learned to Attack Before It Learned to Defend
August 24, 2026

Why AI Learned to Attack Before It Learned to Defend

Fernando Montenegro, VP & Practice Lead at Futurum, shares his insights on how offensive AI succeeds because it's easier to verify than defensive security, shifting the need for vendors to...
Can Frontier Virtual Patching Close the AI Exposure Gap
August 24, 2026

Can Frontier Virtual Patching Close the AI Exposure Gap?

Fernando Montenegro, VP at The Futurum Group, shares insights on how Palo Alto Networks connects AI vulnerability discovery with pre-disclosure network protection....
Brinqa Buys PlexTrac to Put Proof Behind Exposure Management
August 24, 2026

Brinqa Buys PlexTrac to Put Proof Behind Exposure Management

Fernando Montenegro, VP at Futurum, analyzes Brinqa's acquisition of PlexTrac and what adding offensive security validation to an exposure management platform does, and does not, prove about remediation....
Thales CMD 2024: Cybersecurity Ambition Meets a $338B Market
August 22, 2026

Thales CMD 2024: Cybersecurity Ambition Meets a $338B Market

Thales positioned cybersecurity as a core growth pillar at its November 2024 Capital Markets Day, targeting a market expanding from $195B to $338B by 2029 at 11.6% CAGR, driven by...
FPT IS Bets on Vietnam's Data Privacy Law as a Platform Moment
August 22, 2026

FPT IS Bets on Vietnam’s Data Privacy Law as a Platform Moment

Vietnam's strict new data protection laws drive enterprise urgency. FPT IS launches a four-layer Data Privacy Management Platform to meet compliance demands and position itself as a strategic infrastructure partner....
Cloudera Anywhere Cloud Targets Hybrid AI Complexity With In-Place Execution
August 21, 2026

Cloudera Anywhere Cloud Targets Hybrid AI Complexity With In-Place Execution

Brad Shimmin analyzes Cloudera Anywhere Cloud, examining how modular blueprints, Apache Iceberg, and zero-copy lakehouse architectures resolve data gravity and MLOps bottlenecks across hybrid enterprise AI estates....

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.