The rise of agentic AI safety threats is accelerating development for distributors that may assist shield enterprises. Snyk’s Evo software program, the agent-native layer of its core AI safety platform, now accounts for 60% of the corporate’s new deal quantity and is driving a 30% improve in common contract worth.
Evo has additionally sustained an 81.5% month-over-month buyer development price since making it typically obtainable in March 2026. The revelation, which Snyk shared earlier this month, alerts how swiftly enterprises are transferring AI safety from experimentation to manufacturing.
The information additionally underscores organizations’ considerations about mitigating the harm AI brokers may cause. It follows a number of high-profile incidents during which brokers from OpenAI, Anthropic, Google and Meta escaped sandboxes and broke into different firms.
Whereas these incidents had been chalked as much as human negligence associated to weakened agentic controls, many enterprises already discover extra vulnerabilities than their builders can repair.
Snyk’s analysis spanning 4,800-plus clients confirmed that newly launched points rose 108% between This fall 2024 and Q1 2026 earlier than agentic code technology reached full scale. The findings counsel AI is each producing extra code and vulnerabilities than people can evaluate, whereas enabling attackers to find and exploit weaknesses at machine velocity.
Coding brokers introduce a special layer of publicity, pulling in unvetted MCP servers and third-party expertise and executing actions on manufacturing environments with out human approval. Conventional tooling was not constructed to detect such exercise, because it was designed to scan artifacts fairly than the toolchain an agent assembles at runtime, not to mention the actions it takes with it.
“Vulnerabilities are compounding quicker than groups can clear them, and on high of that, brokers add an entire new layer of publicity,” stated Snyk CEO Ken MacAskill. “We constructed Evo lengthy earlier than enterprises knew to ask for it as a result of the reply was by no means about extra AI grading its personal homework — it has to be unbiased validation.”
Scaling agentic AI safety throughout enterprises
Snyk now processes 2.4 million agent supply-chain scans a month and 4.2 million agent habits checks a day throughout greater than 417,000 onboarded machines, in deployments that attain into the Fortune 50.
Whereas enterprise safety software program usually takes two or three quarters to go reside, Evo goes reside in a single quarter. Seventy-six % of consumers who purchased it within the second quarter put in Evo in present workflows and ran it in manufacturing earlier than the quarter closed.
Since July, one of many largest banks within the U.S. has centralized roughly 1,000 inner agent expertise for 50,000 builders constructing purposes with Claude Code. Snyk runs pre-registry threat evaluation and steady scanning throughout the financial institution’s talent registry.
“The sequence is predictable,” stated Snyk CTO Manoj Nair. “An enterprise introduces coding brokers and ships its personal AI purposes. Then it finds that attackers are probing each at machine velocity, chaining the low-severity points the outdated mannequin instructed groups to disregard. Evo covers the event loop, the manufacturing loop and the adversarial loop, as a result of a loop with a lacking phase is a niche an autonomous attacker will occupy.”
The important thing to closing the find-fix hole
Snyk’s structure rests on a single tenet: the generator can not validate itself. A mannequin that writes code, or that grades its personal agent’s habits, has an inherent battle in certifying that the result’s protected to ship. Open supply points remediated by Snyk’s unbiased validation layer merge at a 94% greater price than fixes produced by a frontier mannequin working alone.
Each Evo resolution locations an unbiased, deterministic safety layer beneath the mannequin, combining the velocity and adaptableness of AI with the repeatability, software context and safety intelligence enterprises have to belief the end result. Multi-model by design, Snyk works throughout main mannequin suppliers as a result of the corporate believes that no single mannequin ought to be the final phrase by itself output.
Snyk’s VulnBench analysis discovered that when the identical code and the identical immediate had been run 5 equivalent instances, almost half of the problems flagged by an LLM alone appeared in solely one of many 5 runs; the best-performing mannequin scored 75.4% in opposition to Snyk’s reference set, a 24.6-point hole to full protection.
“Safety groups don’t want one other system that provides findings to an already unmanageable backlog,” stated Nair. “They want a trusted strategy to flip these findings into fixes and to manipulate the AI brokers more and more answerable for constructing and working software program. Evo combines AI-driven motion with the applying context and deterministic validation required to ship outcomes enterprises can belief.”
Three issues, one platform
Evo applies its shared context and deterministic validation in three options throughout three related safety issues: untrusted agentic growth, ungoverned AI purposes and automatic AI assaults.
Snyk’s Evo Agentic AppSec places safety brokers to work in opposition to the applying safety backlog. Usually obtainable, Secrets and techniques Detection identifies uncovered credentials earlier than they ship. The Remediation Agent, at present in open preview, routinely fixes the problems it finds. The Agentic AppSec Agent, in personal preview, orchestrates these capabilities right into a steady autonomous triage-and-remediation loop.
Evo Agentic Growth Safety governs the agentic growth course of itself. Coding brokers more and more pull in third-party instruments, execute actions and generate manufacturing code, usually with out satisfactory controls over what they might entry. Evo validates instruments earlier than they’re trusted, governs agent habits contained in the execution loop and secures generated code in the meanwhile it’s written. Evo AI-SPM offers safety groups a reside stock of the fashions, brokers and AI purposes working throughout their environments, together with the insurance policies and auditability required to manipulate them.
Collectively, the three options set up a steady safety mannequin for the agentic software program lifecycle: uncover each agent, mannequin and AI software within the setting; remediate the backlog that already exists; validate the instruments, code and fixes brokers produce earlier than they’re trusted; and stop new publicity in the meanwhile it’s launched.
Evo Steady Offensive Safety exams that structure repeatedly. It assaults an enterprise’s defenses to substantiate that insurance policies, controls and guardrails maintain below real-world adversarial stress and can’t be bypassed by agent manipulation. Snyk’s product suite comes at a vital time.
Gartner predicts that ungoverned AI agent abuse will drive 25% of enterprise breaches by 2028. Whereas the researcher says it will result in mandated adoption of zero-trust governance and agent-specific kill-switches, Snyk might help present extra assurance that firms are defending their information and IP.
