Snyk’s Volume II State of Agentic AI Adoption report makes a simple point that should change enterprise AI reviews: the model list is not the inventory. The report analyzed more than 3,000 enterprise accounts and about 1.39 million repositories, then concluded that most security teams see only about one-third of their organization’s actual AI footprint.
The missing surface is not exotic. It includes agent frameworks, MCP servers, retrieval systems, vector databases, datasets, and supporting tools that invoke or extend models. Snyk says the complete AI surface is roughly three times larger than a model inventory alone would suggest. It also reports that organizations running agentic architecture rose from 28 percent in January 2026 to 33 percent in Volume II, while adopters running both agent frameworks and MCP servers increased from 36 percent to 50 percent.
Grey Haven’s read: this is the predictable cost of treating AI governance as vendor approval. Enterprises can know which LLMs are permitted and still have no working map of what is calling them, what data those systems can reach, and which tool paths can take action.
For operators, the first control is not a better prompt policy. It is an AI bill of materials that covers orchestration layers, model calls, retrieval stores, datasets, MCP endpoints, credentials, and downstream APIs. If that inventory cannot connect a deployed agent to its data lineage and execution permissions, the organization is not governing an AI system. It is governing a logo.
Watch for security and platform teams to shift from “approved models” to runtime and repository-level AI composition. The winners will be the teams that can answer what exists, what it can touch, and how to disable it before a review meeting turns into incident response.
Source: Snyk, “Enterprises Are Blind to Two-Thirds of Their Own AI Attack Surface.”