O
OOMeta
← Back to Insights

August 2026 · 7 min read

Capability-Tiered Governance: Snyk's 3,044-Firm Study

Capability-Tiered Governance: Snyk's 3,044-Firm Study

Key Definitions

Capability-Tiered Governance The next governance discipline proposed by Snyk's report: applying different controls based on a model's autonomous capability — not its provider or use case. A program built for an ECI-130 model is not adequate for an ECI-155 model, yet the same enterprise often runs both without distinguishing them in policy.

ECI (Epoch Capabilities Index) An external scoring system from Epoch AI measuring a model's potential for autonomous task completion. The frontier ECI as of April 2026 was 160; the weighted average ECI of deployed proprietary models was 135.4, 24.6 points below the frontier, largely due to older models kept in production for cost or stability (e.g., gpt-3.5-turbo, claude-3-opus).

Data Lineage A code-level link between a model and the training or fine-tuning data that shaped it. The report found roughly 0.36 declared datasets per model, and only 783 of 1,541 model-deploying accounts (50.8%) declared any datasets — about half of deploying organizations cannot explain how their AI systems reach outcomes.

In August 2026, Snyk released its 2026 State of Agentic AI Adoption Volume II, expanding the sample from roughly 500 environments in Volume I to 3,044 enterprise accounts and about 1.39 million code repositories. The report advances a governance proposition few have articulated: the governance unit is no longer the model response — it is the operational behavior of the system — and the correct dimension for configuring controls is a model's autonomous capability (its ECI score), not its provider or use case. This is the beginning of capability-tiered governance as the next discipline.

A Bigger Sample, the Same Structural Thesis

Volume II confirms Volume I's core thesis with a larger, more geographically diverse dataset: across 3,044 accounts, 33.0% (1,004) show evidence of agentic architecture; restricted to the 2,142 accounts with any AI surface, that rises to 46.9% — nearly half of AI-active organizations are agentic. And 50.3% of agentic adopters run both agents and MCP (up from 36% in Volume I). Enterprise AI is no longer just "chat"; it is a full-stack execution platform embedded in operations.

The defining shift from Volume I to Volume II is not just growth in AI usage. It is the transition from AI as an application feature to AI as an interconnected execution system composed of models, agents, orchestration frameworks, external tools, retrieval layers, and autonomous infrastructure. A single agent with tool-invocation permissions and data access can produce thousands of autonomous actions per day — the governance unit is not the asset, but the capability embedded in the asset.

Capability-Tiered Governance: Controls by ECI, Not Provider

The report introduces a capability-scoring dimension for the first time, using Epoch AI's ECI (Capabilities Index) to measure a model's potential for autonomous task completion. The frontier ECI as of April 2026 was 160. The weighted average ECI of deployed proprietary models was 135.4 — 24.6 points below the frontier — dragged down by a long tail of older models (gpt-3.5-turbo, claude-3-opus) kept in production for cost or stability.

The distribution of capability is the governance challenge

A program built for an ECI-130 model is not adequate for an ECI-155 model, yet the same enterprise often runs both without distinguishing them in policy. Capability-tiered governance — not use-case-tiered — is likely to become standard practice within 12 months.

Frontier-adjacent deployments need tighter oversight

Narrower permission scopes, more rigorous evaluation, and more sophisticated monitoring than the conservative core — the more capable the model, the more constrained its operating envelope should be.

The lineage gap is the governance gap

Only 50.8% of model-deploying organizations declare any datasets. Bias assessment, regulatory compliance, audit response, and IP assurance all depend on knowing what data shaped a model's behavior — without it, governance has no foundation.

Three Direct Implications for Enterprises

First, agentic adoption is mainstream, not marginal — nearly half of AI-active enterprises already run agentic architectures, and governance is universally lagging. Second, governance must be capability-tiered: applying the same controls to models of very different autonomy either over-constrains low-cost use cases or leaves a control gap on the most capable models. Third, data lineage is the underlying asset of governance: until you can explain how a model reaches an outcome, any bias assessment, audit, or incident investigation is guesswork.

OOMeta's View

Snyk's report is valuable because it advances the governance metric from "what model are you using" to "how autonomous is that model." For enterprises, this translates into an actionable shift: tag every model with a capability score (ECI or equivalent) and configure permission scope, evaluation frequency, and monitoring intensity accordingly; meanwhile, treat data lineage as a hard prerequisite of governance — first solve "I know why it behaves this way," then "I can control what it does." Capability-tiering and data lineage are the two new anchors of governance in the age of agent deployment at scale.

References: Snyk, "2026 State of Agentic AI Adoption - Volume II", 2026-08, https://res.cloudinary.com/snyk/image/upload/v1785759343/Volume_II-2026_The_State_of_Agentic_AI_Adoption_August_2026_a9jyao.pdf

Frequently Asked Questions

How much data does this report analyze?+

Snyk's 2026 State of Agentic AI Adoption Volume II expands to 3,044 enterprise accounts across the Americas, EMEA, and Asia-Pacific, and approximately 1.39 million code repositories analyzed in June 2026 — a major expansion from the roughly 500 environments in Volume I.

What is the agentic adoption rate?+

Across 3,044 accounts, 33.0% (1,004 accounts) show evidence of agentic architecture — agent frameworks, MCP servers, or both. Restricted to the 2,142 accounts with any detected AI surface, adoption rises to 46.9%. Of agentic adopters, 50.3% run both agents and MCP.

What is capability-tiered governance?+

Applying different controls based on a model's autonomous capability (ECI score), not its provider or use case. The report says a program built for an ECI-130 model is not adequate for an ECI-155 model; frontier-adjacent deployments need narrower permission scopes, more rigorous evaluation, and stronger monitoring.

How serious is the data lineage gap?+

Only 783 of 1,541 model-deploying accounts (50.8%) declare any datasets in their repositories. About half of model-deploying organizations have no visible code-level link to training or fine-tuning data — yet bias assessment, compliance audits, incident investigation, and IP assurance all depend on knowing what data shaped a model's behavior.

How has the governance unit changed?+

The report's core thesis: the governance unit is no longer the model response — it is the operational behavior of the system. The enterprise AI stack is evolving from application features into interconnected execution systems composed of models, agents, orchestration frameworks, external tools, retrieval layers, and autonomous infrastructure, and the governance challenge is evolving with it.