September 2026 · 7 min read
Snyk Vol II: AI's real footprint is 3x model counts

Key Definitions
AI-BOM (AI Bill of Materials) A software-BOM-style inventory of the components in an AI system — models, agent frameworks, MCP servers, datasets and tools — used to inventory and audit the AI supply chain.
ECI (Epoch Capabilities Index) Epoch AI's capability index quantifying a model's potential for autonomous task completion. The frontier stood at 160 in April 2026; the weighted average of deployed proprietary models was 135.4.
MCP (Model Context Protocol) An open protocol connecting AI agents to tools, services and data. Among organizations on agentic architectures, over half run both agents and MCP — MCP is becoming the connective tissue of the agentic enterprise.
Snyk has published Volume II of the State of Agentic AI Adoption: AI-BOM telemetry from 3,044 enterprise accounts across the Americas, EMEA and Asia-Pacific — approximately 1.39 million code repositories analyzed in June 2026. The structural thesis from Volume I's 500+ environments — AI is no longer deployed as isolated features but as interconnected execution systems with their own supply chains, dependencies and emerging autonomous behavior — has now been validated twice, across three regions.
Four counterintuitive numbers
33% are agentic, and adopters are going all-in
33.0% of organizations use agentic architectures (agent frameworks or MCP servers), up from 28.4% in Volume I; restricted to the 2,142 accounts with any AI surface, adoption rises to 46.9%. The composition is the deeper story: 50.3% of adopters run both agents and MCP — up from 36%. Agentic adoption is not just spreading; it is deepening into full-stack execution platforms.
The footprint is about 3x the model count
Measured by models alone, AI density is roughly 0.080 components per repository; including the full operational stack — frameworks, MCP servers, retrieval systems, vector databases, datasets, tools — it rises to about 0.241. Each deployed model averages about two accompanying components. Models are the visible tip; the composition is the iceberg.
The provider landscape is no longer two-vendor
OpenAI's share of model occurrences fell from 43.6% to 34.0%; Anthropic rose from 3.5% to 10.5%; the top four still total about 71%. The two-vendor world of late 2025 is giving way to a wider, more distributed core.
AI is a growing share of engineering work
AI assets per developer rose from 0.18 in Volume I to 0.30 — roughly one per 3-4 developers — a two-thirds increase in density in six months. AI has moved from experiment to routine engineering load.
Capability: conservative deployments, frontier already in production
Volume II introduces capability for the first time, scoring deployed models with Epoch AI's ECI (frontier 160 as of April 2026). The weighted average of deployed proprietary models is 135.4 — about 25 points below the frontier, dragged down by a long tail of older models (gpt-3.5-turbo, claude-3-opus) kept for cost or stability. But frontier-adjacent deployments (155-159 ECI) were observed 1,874 times, all proprietary — the leading edge is already in production. Open-weight models trail the closed frontier by about 4 months / 8 ECI points. The takeaway: the local/open-versus-frontier tradeoff is becoming a core architecture decision, and governance should be tiered by capability, not just count.
The lineage gap is the governance gap
The report's most uncomfortable number: only 50.8% of model-bearing accounts declare any dataset in their repositories, at about 0.36 datasets per model. Roughly half of model-deploying organizations have no visible code-level link to the data that shaped their models — in every region. Bias assessment, regulatory compliance, audit response, incident investigation and IP assurance all depend on knowing what data shaped a model's behavior. The report draws the software analogy plainly: enterprise AI is evolving along the same path as every major infrastructure transition — from isolated experimentation, to operational dependence, to systemic criticality. The difference is that these systems are becoming autonomous while the transition is still unfolding.
Supply chain: external dependencies dominate
77.4% of AI tools come from third-party packages, about 3.4:1 over custom tools. AI supply chain security is software supply chain security with new, behavioral dimensions. For governance leaders this means model-focused governance covers about a third of the real footprint — datasets, tools, frameworks and third-party packages all contribute meaningfully to the risk profile.
What it means for enterprises
The governance unit changes: from model response to system behavior
Generative systems produced outputs for human consumption; agentic systems invoke tools, retrieve information, coordinate workflows and execute actions autonomously. The governance unit is no longer the model response — it is the operational behavior of the system. Inventory, authorization and monitoring must follow.
The MCP governance window is now
With \"both\" now the majority pattern, MCP has moved from interesting protocol to the connective tissue of the agentic enterprise. The window to develop MCP-specific governance — before the deployment base outgrows retrofitting — is now.
Answer the nine questions before you scale
The report hands governance leaders nine questions: your full AI inventory (not just models), which systems are agentic and what they can do, provider concentration, capability distribution, open/local alternatives, data lineage per production model, and behavioral-change detection. What you cannot answer is next quarter's exposure.
The bottom line
The report's value is not in any single number but in the ratios: models are a third of the real AI footprint; half of deployers cannot trace their data; frontier models are already running in production. Enterprise AI governance is becoming a distinct operational discipline — adjacent to but different from application security, cloud governance and software supply chain. Its object is interconnected autonomous systems whose behavior emerges from models, tools, datasets, orchestration and external services. Govern by model inventory alone, and you are managing the tip of the iceberg.
References
- Snyk: 2026 State of Agentic AI Adoption — Volume II (2026-08) — https://res.cloudinary.com/snyk/image/upload/v1785759343/Volume_II-2026_The_State_of_Agentic_AI_Adoption_August_2026_a9jyao.pdf
FAQ
Where does this report's data come from?+
Snyk analyzed AI-BOM telemetry from 3,044 enterprise accounts across the Americas, EMEA and Asia-Pacific — roughly 1.39 million code repositories — sampled in June 2026, compared against Volume I (500+ environments) from January 2026.
What is the actual agentic adoption rate?+
33.0% of organizations use agentic architectures (agent frameworks or MCP servers), up from 28.4% in Volume I; among organizations with any AI surface, adoption rises to 46.9%. Of adopters, 50.3% run both agents and MCP, up from 36%.
What does "footprint is 3x model counts" mean?+
Measured by models alone, AI density is about 0.080 components per repository; including the full operational stack (frameworks, MCP servers, retrieval systems, vector databases, datasets, tools) it rises to about 0.241 — models are roughly a third of the real AI footprint, and each deployed model averages about two accompanying components.
How has the provider landscape changed?+
OpenAI's share of model occurrences fell from 43.6% to 34.0%; Anthropic rose from 3.5% to 10.5%; the top four still account for about 71%. The "two-vendor world" of late 2025 is giving way to a wider, more distributed core.
Why is the lineage gap the governance gap?+
Only 50.8% of model-bearing accounts declare any dataset in their repositories, with about 0.36 datasets per model — roughly half of model-deploying organizations cannot explain what data shaped their models. Bias assessment, regulatory compliance, audit response, incident investigation and IP assurance all depend on that traceable chain.
What should enterprises do?+
Start with the report's nine questions: your full AI inventory (not just models), which systems are agentic and what they can do, provider concentration, the capability distribution of deployed models, open/local alternatives, data lineage for every production model, and how you would detect behavioral change in an AI system.
Related Articles
Why agents fail in production: the SOP-Bench lesson
SOP-Bench: 2,000+ business tasks across 12 domains. Newer models aren't always better, extra tools hurt, no single agent excels. Evaluate per task pre-deploy.
Toyota's 50+ Agents: Platform Speed Hides a Single Risk Gate
Toyota cut agent delivery from 6 months/6 engineers to 4 days/1. Savings came from approval and plumbing; one inherited permission gate now guards them all.
Salesforce: Agent ROI Favors Preparation Over Speed
2,025-respondent study: first deploy doesn't mean first ROI (~8 months). Winners: clean data access, bounded agent scope, escalation paths — not model quality.
Microsoft ThinkingBox: The 40-Point Agent Reliability Gap
ThinkingBox: GPT-5.4 solves a task 65% once but only 25% across 20 trials. Agents log clean runs they failed — transcript evals overstate capability.