Breaking News

Snyk’s Evo Reaches 60% of New Deal Volume As AI Risks Soar

https://ift.tt/gxRyIHt

The rise of agentic AI security threats is accelerating growth for vendors that can help protect enterprises. Snyk’s Evo software, the agent-native layer of its core AI security platform, now accounts for 60% of the company’s new deal volume and is driving a 30% increase in average contract value.

Evo has also sustained an 81.5% month-over-month customer growth rate since making it generally available in March 2026. The revelation, which Snyk shared earlier this month, signals how swiftly enterprises are moving AI security from experimentation to production.

The news also underscores organizations’ concerns about mitigating the damage AI agents can cause. It follows several high-profile incidents in which agents from OpenAI, Anthropic, Google and Meta escaped sandboxes and broke into other companies.

While those incidents were chalked up to human negligence related to weakened agentic controls, many enterprises already find more vulnerabilities than their developers can fix.

Snyk’s research spanning 4,800-plus customers showed that newly introduced issues rose 108% between Q4 2024 and Q1 2026 before agentic code generation reached full scale. The findings suggest AI is both generating more code and vulnerabilities than humans can review, while enabling attackers to discover and exploit weaknesses at machine speed.

Coding agents introduce a different layer of exposure, pulling in unvetted MCP servers and third-party skills and executing actions on production environments without human approval. Traditional tooling was not built to detect such activity, as it was designed to scan artifacts rather than the toolchain an agent assembles at runtime, let alone the actions it takes with it.

“Vulnerabilities are compounding faster than teams can clear them, and on top of that, agents add a whole new layer of exposure,” said Snyk CEO Ken MacAskill. “We built Evo long before enterprises knew to ask for it because the answer was never about more AI grading its own homework — it has to be independent validation.”

Scaling agentic AI security across enterprises

Snyk now processes 2.4 million agent supply-chain scans a month and 4.2 million agent behavior checks a day across more than 417,000 onboarded machines, in deployments that reach into the Fortune 50.

While enterprise security software typically takes two or three quarters to go live, Evo goes live in a single quarter. Seventy-six percent of customers who bought it in the second quarter installed Evo in existing workflows and ran it in production before the quarter closed.

Since July, one of the largest banks in the U.S. has centralized roughly 1,000 internal agent skills for 50,000 developers building applications with Claude Code. Snyk runs pre-registry risk assessment and continuous scanning across the bank’s skill registry.

“The sequence is predictable,” said Snyk CTO Manoj Nair. “An enterprise introduces coding agents and ships its own AI applications. Then it finds that attackers are probing both at machine speed, chaining the low-severity issues the old model told teams to ignore. Evo covers the development loop, the production loop and the adversarial loop, because a loop with a missing segment is a gap an autonomous attacker will occupy.”

The key to closing the find-fix gap

Snyk’s architecture rests on a single tenet: the generator cannot validate itself. A model that writes code, or that grades its own agent’s behavior, has an inherent conflict in certifying that the result is safe to ship. Open source issues remediated through Snyk’s independent validation layer merge at a 94% higher rate than fixes produced by a frontier model working alone.

Every Evo solution places an independent, deterministic security layer beneath the model, combining the speed and adaptability of AI with the repeatability, application context and security intelligence enterprises need to trust the outcome. Multi-model by design, Snyk works across leading model providers because the company believes that no single model should be the last word on its own output.

Snyk’s VulnBench research found that when the same code and the same prompt were run five identical times, nearly half of the issues flagged by an LLM alone appeared in only one of the five runs; the best-performing model scored 75.4% against Snyk’s reference set, a 24.6-point gap to full coverage.

“Security teams do not need another system that adds findings to an already unmanageable backlog,” said Nair. “They need a trusted way to turn those findings into fixes and to govern the AI agents increasingly responsible for building and operating software. Evo combines AI-driven action with the application context and deterministic validation required to deliver outcomes enterprises can trust.”

Three problems, one platform

Evo applies its shared context and deterministic validation in three solutions across three connected security problems: untrusted agentic development, ungoverned AI applications and automated AI attacks.

Snyk’s Evo Agentic AppSec puts security agents to work against the application security backlog. Generally available, Secrets Detection identifies exposed credentials before they ship. The Remediation Agent, currently in open preview, automatically fixes the issues it finds. The Agentic AppSec Agent, in private preview, orchestrates these capabilities into a continuous autonomous triage-and-remediation loop.

Evo Agentic Development Security governs the agentic development process itself. Coding agents increasingly pull in third-party tools, execute actions and generate production code, often without adequate controls over what they may access. Evo validates tools before they are trusted, governs agent behavior inside the execution loop and secures generated code at the moment it is written. Evo AI-SPM gives security teams a live inventory of the models, agents and AI applications operating across their environments, along with the policies and auditability required to govern them.

Together, the three solutions establish a continuous security model for the agentic software lifecycle: discover every agent, model and AI application in the environment; remediate the backlog that already exists; validate the tools, code and fixes agents produce before they are trusted; and prevent new exposure at the moment it is introduced.

Evo Continuous Offensive Security tests that architecture continuously. It attacks an enterprise’s defenses to confirm that policies, controls and guardrails hold under real-world adversarial pressure and cannot be bypassed through agent manipulation. Snyk’s product suite comes at a critical time.

Gartner predicts that ungoverned AI agent abuse will drive 25% of enterprise breaches by 2028. While the researcher says this will lead to mandated adoption of zero-trust governance and agent-specific kill-switches, Snyk can help provide additional assurance that companies are protecting their data and IP.

 

The post Snyk’s Evo Reaches 60% of New Deal Volume As AI Risks Soar appeared first on SD Times.



Tech Developers

No comments