AI Readiness

Your Real AI Footprint Is About 3x Bigger Than Your Model List

Snyk's latest telemetry shows the AI you can name is a fraction of the AI you are actually running.

By Harrison Painter August 5, 2026 Updated August 5, 2026 8 min read

If you asked your team today which AI you are running, most would hand you a list of models. ChatGPT here. Claude there. Maybe a copilot bolted onto a few workflows. It feels like a complete answer.

It is roughly a third of one.

Snyk published the second volume of its State of Agentic AI Adoption report on August 3, 2026. The finding underneath it is the kind of thing a CEO should read twice. When you measure an enterprise at the system level, the real AI footprint comes back about three times larger than a model-only count. And the security teams whose job is to watch that footprint can see only about a third of it. The other two-thirds runs unseen.

One thing is worth holding onto if you feel behind on this. The biggest companies do not know what they are running either. By Snyk's own measurement, "behind" is the industry baseline right now, not a personal failing.

What did Snyk actually measure?

Snyk did not run an opinion survey. It analyzed anonymized AI-BOM telemetry data from 500+ Evo scans (from a subset of pre-approved customers / early adopters), building an AI bill of materials from what is actually deployed. Volume II draws on more than 3,000 enterprise accounts worldwide and 1.39 million code repositories scanned since May 2026. This is telemetry, not a show of hands.

That is important because most of what leaders "know" about their AI use comes from what people report. This came from looking directly at the code, the services, and the connections already in production.

One caveat, stated plainly. Snyk sells the discovery product that produces these numbers, so it benefits from you believing you have an unseen AI footprint. That does not make the data wrong. It came from real scans of thousands of real environments. It does mean the three-times figure is a single vendor's measurement, not an independently audited one. Read it as a strong signal, and count your own house to confirm it.

Why is most of your AI footprint invisible?

The short version: AI does not arrive as one clean tool. It arrives as a stack. A model is the piece everyone can name, so it becomes the whole story in people's heads. The rest of the stack gets built, connected, and shipped without ever showing up on a model list.

Snyk's Chief Technology and Innovation Officer, Manoj Nair, put it in one line.

"Models are the visible tip. The composition is the iceberg."

The composition is where the surprise lives. When a security team says they see about a third of the footprint, they are not being careless. They are watching the models. The models were never the hard part to see.

What is an agentic AI stack actually made of?

Ask most executives to picture their AI and they picture a chatbot. The systems going into production in 2026 look different. Beyond the language model, an agentic setup pulls in several other moving parts:

  • Agent frameworks that let the AI take steps on its own rather than just answer a prompt.
  • MCP servers, the connectors that hand an agent access to your tools, files, and systems.
  • Retrieval systems and vector databases that feed the model your company's own information.
  • Datasets the model was trained or tuned on.
  • Supporting tooling and packages, most of it pulled in from outside your walls.

Each of those is a real thing running in your business. Each carries its own access, its own failure modes, and its own supply-chain risk. None of them is a "model," so none of them shows up when someone counts models.

And this stack is filling out fast. Snyk found that among organizations that have adopted agentic architecture at all, full-stack adoption, meaning agent frameworks paired with MCP servers, climbed from 36% in January 2026 to 50% by August. The half that connected everything did so in about seven months.

How fast is this moving across the market?

Fast enough that a wait-and-see posture is quietly becoming a decision.

Agentic adoption across all organizations rose from 28% in January 2026 to 33% by August. Volume I framed the same reality a different way: one in four organizations had already moved past prompt-based AI toward systems that act on their own. That was the earlier read. The number has only gone up since.

The takeaway for a P&L owner is not "adopt faster." It is that the ground under your competitors and your own teams is changing every quarter, and the parts changing fastest are the parts nobody is counting.

Which AI models are enterprises actually using?

There is a real movement in who supplies the models, and it is worth a board-level glance.

Between January and August 2026, Anthropic's share of enterprise model usage rose from 4% to 11%. Over the same stretch, OpenAI's share fell from 44% to 35%. OpenAI is still the largest single provider by a wide margin. But a field where one vendor's share nearly tripled in seven months while the leader's slipped is a field still being decided, not a settled one.

If you are choosing a tool and feeling anxious about picking wrong, read that as permission. The enterprises with the most resources are still moving between providers. You are not late to a locked-in market. You are early to one that is still forming.

Where the real exposure sits

Two numbers from the report point straight at the risk, and both are the kind a leader can act on without a technical degree.

First, roughly three-quarters of AI tools are sourced from outside the organization. That is a software supply chain your existing security tools were mostly not built to watch. When most of your AI comes from vendors and open packages, you inherit their weaknesses along with their features.

Second, only about half of model-deploying organizations declare any training dataset in their code repositories. Think about what that means for a moment. Half of these companies cannot easily answer a basic question: what data taught the AI we are trusting to make decisions? That is a knowing-your-own-business problem first, and a security one second.

The distance between what gets deployed and what gets governed is widening, and it widens quietly. Nobody schedules a meeting to add an ungoverned MCP server. It just gets shipped because it made a workflow faster.

What does this mean for a leader who feels behind?

It means the anxiety you may carry about AI is aimed at the wrong target.

The fear most professionals describe is falling behind on the tools. Learn the newest model, master the newest feature, or get left in the dust. This report points the exposure somewhere else. The real problem is the sprawl almost everyone has already lost track of, and that includes the leaders you assume have it figured out. The newest tool you have not learned yet barely registers next to it.

That reshapes the job. The valuable skill in 2026 is being able to count what you have, see how the pieces connect, and decide what is worth governing. That is a real capability, and it is a learnable one.

Counting your own system and understanding how the parts talk to each other is a specific level of skill. In The 7 Levels of AI Proficiency, it lives with the people who think in systems rather than single tools, the ones who can look at a sprawl of models, agents, and connectors and draw the actual map. A handful of people in any organization can operate at that level, and the ones that pull ahead make it a habit.

How do you get a handle on your AI footprint?

You do not need Snyk's product to start. You need one honest inventory. Here is a version any leader can run this quarter without writing a line of code.

Count more than models. Ask your teams not just which AI tools they use, but what those tools connect to. Every integration, every data source, every automation that runs without a human pressing go. Expect the list to be longer than you thought. Snyk's whole point is that it will be.

Ask where each piece came from. Built in-house or bought? If bought, from whom, and what does it have access to? Given that roughly three-quarters of AI tooling comes from outside, this is where most of the unseen risk lives.

Ask what data feeds it. For any AI touching customer information, money, or decisions, someone should be able to name the data behind it. If half the market cannot, and you can, you are already ahead of the baseline.

Decide what needs a watcher. You will not govern everything, and you do not need to. Sort the inventory by what would actually hurt if it failed or leaked, and put real oversight on that slice first.

This is the same discipline that makes any AI project pay off. Map the system before you automate it. You cannot secure, budget for, or scale something you have never counted. The companies that win the next few years are not the ones with the most AI. They are the ones that know what AI they have.

Related reading: Level 6: The Admiral (Systems Integrator).

Sources

  1. Snyk 2026 State of Agentic AI Adoption, Volume II
  2. Snyk State of Agentic AI Adoption (Volume I overview page)
  3. Manoj Nair, Snyk contributor page

Frequently Asked Questions

Is the "3x" number reliable?

It comes from Snyk's own telemetry across more than 3,000 enterprise environments, so it rests on real data rather than a survey. It is also a single vendor's finding, and that vendor sells the discovery tool. Treat it as a strong directional signal and verify it against your own inventory.

What is an MCP server, in plain terms?

It is a connector that gives an AI agent access to your tools, files, and systems so it can take action rather than only answer questions. It is one of the fastest-growing parts of the stack and one of the least visible on a model list.

We only use a couple of chatbots. Does this apply to us?

It may apply less, and that is fine. The report is about organizations moving into agentic AI, where agents act on their own. If you are early, this is the moment to build the counting habit before the stack grows past what anyone can track.

Should we switch AI model providers based on the share numbers?

No. The share movement tells you the market is still being decided, which is useful context for a leader. It is not a reason to change vendors. Choose based on the job you need done and the data you are willing to share.

Harrison Painter, Executive AI Advisor
Harrison Painter
Executive AI Advisor. Founder, LaunchReady.ai and AI Law Tracker.

Harrison is an Indiana AI Advisor who helps business owners and executives get their time back by building AI systems that run the work for them. Nearly 20 years in business and author of You Have Already Been Replaced by AI. Creator of The 7 Levels of AI Proficiency.

Connect on LinkedIn

Find your AI Proficiency level

The free 7 Levels assessment places you across seven stages of AI capability. Under ten minutes. Research-backed scoring.

Get the weekly briefing

LaunchReady Indiana delivers AI news, compliance updates, and case studies for Indiana leaders. Every Tuesday. Five minutes.

Subscribe free