Your AI footprint is 3x what your model inventory shows
Snyk's agentic AI research finds enterprises can see about a third of their real AI footprint. The missing two-thirds are MCP servers, vector stores, and agent frameworks.
Ask most teams what AI they're running and you'll get a list of models. That list is the smallest part of the answer. Snyk's State of Agentic AI Adoption research puts a ratio on it: a system-level view reveals an AI footprint three times larger than model-only counts. Which means if you're inventorying models, you're seeing roughly a third of what you've actually deployed.
What actually happened
Snyk built the first volume from more than 500 anonymized AI discovery assessments, and found that one in four organizations had already moved past prompt-based AI into autonomous systems. Volume II, covered by analyst firm Futurum in August, sharpens the picture: enterprises can identify only about 33% of their real AI footprint, and adoption of full-stack agentic architectures nearly doubled over six months.
The governance numbers are the other half. Per Futurum's read of the report, 56% of organizations have a dedicated AI governance council, 45% run regular audits of their AI programs, and 10% have taken no formal governance steps at all.
The missing two-thirds aren't exotic. They're the plumbing an agent needs to do anything useful: MCP servers, agent frameworks, retrieval systems, vector databases, datasets, and the tools wired into all of it. Nobody filed a request to deploy those. They arrived as dependencies of something a developer was already approved to build.
Why it matters for your business
A model endpoint is a metered API call with a bill attached — easy to find, easy to govern. An MCP server is a process on your network holding credentials to your CRM, your file store, or your database, and it shows up in nobody's model inventory. That asymmetry is the whole finding. The parts of your AI stack that hold real access are precisely the parts your existing inventory doesn't count.
You don't need a governance council to fix this. You need one afternoon and a list. Grep your repos for MCP server configs and agent framework imports. List every vector store and retrieval index and note what data went into it. For each one, write down two things: which credentials it holds, and who can revoke them. Most teams find something they forgot about in the first hour — a prototype MCP server still running with a long-lived token, an index built from a customer export that was supposed to be temporary.
The reason this matters more for a 20-person company than a 2,000-person one: you have no security team doing this in the background. The blind spot is the same size proportionally, and there's nobody else looking. The good news is the inventory is small enough to hold in a spreadsheet — as long as you build it before the footprint doubles again.
Key takeaways
- Snyk's research finds the real AI footprint is roughly 3x what a model-only inventory shows — enterprises identify about 33% of it
- The invisible two-thirds are MCP servers, agent frameworks, retrieval systems, vector databases, and their datasets
- Full-stack agentic architecture adoption nearly doubled in six months; 10% of organizations have taken no formal governance steps
- Inventory by credential, not by model: for every AI component, record what it can reach and who can revoke it
- Small teams have the same blind spot with nobody watching it — but a small enough stack to actually enumerate
Not sure what your agents can actually reach? We map the AI components already running in your business — MCP servers, indexes, tokens — and put revocable, scoped credentials behind each one. Start with an audit or see how we scope agent access.
Sources: Snyk — State of Agentic AI Adoption, Futurum Group.
- #ai-governance
- #ai-agents
- #mcp
- #shadow-ai
- #ai-security
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Valar Atomics raises $1B: your AI bill is a power bill
Sequoia led a $1B round at a $6B valuation for factory-built nuclear reactors aimed at AI data centers. Why compute scarcity is now an electricity problem.
Read itRunware's shipping-container data center for AI inference
Runware unveiled a portable AI inference pod: 1,200 GPUs and 1MW in a 20-foot container, built in weeks. Why where your inference runs sets your latency and price.
Read it