Enterprise AI Governance: A Blind Spot in AI Model Visibility

A comprehensive study conducted by AI security firm Snyk has uncovered a significant blind spot in enterprise AI governance. Astonishingly, approximately 50% of enterprise accounts do not have any AI model declared in their code. However, most are actively utilizing AI through third-party services, packages, and tools. These insights are part of Snyk’s 2026 State of Agentic AI Adoption: Volume II report, which examined 1.39 million code repositories across 3,044 enterprise accounts globally.

According to the report, security teams typically only see about one-third of their organization’s actual AI footprint. Enterprises are deploying more than just large language models (LLMs). They are also implementing agent frameworks, Model Context Protocol (MCP) servers, retrieval systems, vector databases, and external tools. These elements are not usually included in standard model inventories. The report found agentic AI architectures operating in 33% of enterprise environments, with full-stack deployments of AI agents and MCP infrastructure nearly doubling since January 2026.

The study also highlighted that OpenAI continues to be the most popular model provider. However, Anthropic and other vendors are increasing their enterprise market share. The top four AI providers account for approximately 71% of identifiable model deployments. Snyk cautions that this “AI visibility gap” signifies a large and expanding attack surface that most governance programs are ill-prepared to handle.

Source: Help Net Security — Your enterprise AI footprint is about three times bigger than your model list

Move to the category:

Leave a Reply

Your email address will not be published. Required fields are marked *