Rows of black server racks with blue network cables in a data center.
← Back to Blog
AI Governance

The AI Agent Governance Gap Just Got a Number

Head portrait of Alex Goryachev
Alex Goryachev·August 5, 2026·4 min read

Snyk measured 3,044 enterprises. The real AI footprint is 3 times larger than the official model list. About half of firms cannot link a model to the data that trained it.

Key Takeways

  • Snyk found the real enterprise AI footprint is about 3 times bigger than the model lists firms keep.
  • About 50% of firms cannot link the AI models they run to the data that trained them.
  • About 82% of firms already have unknown or unapproved AI agents in production, per figures cited at Black Hat USA 2026.
  • Zenity, Snyk, Airlock Digital, Drata, and Redpanda all shipped agent governance tools inside 48 hours.

Ask your security lead one question this week. Which AI models run inside our company, and what data trained them? About half of large firms cannot answer the second part. That gap has a name. It is the AI agent governance gap, and it got measured this week.

Snyk published Volume II of its State of Agentic AI Adoption report on August 5, 2026. The study covers 3,044 firms and 1.39 million code repositories. 47% now run agentic AI. The real AI footprint is about 3 times bigger than the model lists firms keep. And roughly 50% cannot tie the models they run back to the data that trained them.

Sit with that second half for a moment. A firm that cannot trace a model to its training data cannot answer a customer who asks what taught it. It cannot answer a regulator either. And when something goes wrong, the fix starts with a guess.

Watch what happens when an auditor asks for the model list. It lands on one analyst with a spreadsheet and a deadline. She pulls the approved names. Then she walks the floor. She finds tools nobody wrote down. The list was never wrong on purpose. It covered what came in the front door.

Those unlisted tools have a name. Shadow AI is employee innovation in real time, and it now has agents in it. Reporters at Black Hat USA this week cited a number worth sitting with. About 82% of firms already have unknown or unapproved AI agents running in production.

None of this is a future risk. The agents are running now, inside firms that believe they have a handle on this. The 3x number is the part that should keep a board awake. It says the map is smaller than the country.

The framework is voluntary. The market already moved.

One day before the Snyk report, the White House released its voluntary AI safety testing framework. It asks firms to run a 30-day test window before release, on their own schedule, by choice. The instinct behind it is right. The clock is generous.

The market did not wait for that clock. In 48 hours, 5 companies shipped against the same gap.

Zenity raised a $125M Series C on August 3 to secure agent identity. Snyk launched Evo on August 4, a product that keeps pen-testing agents after they ship. Airlock Digital showed Agentic AI Control and Governance at Black Hat the same day, watching agent commands at the endpoint. Drata put AI Agent Governance into limited release, for finding agents and holding them to policy. Redpanda began enforcing policy at the Model Context Protocol boundary, which sets what each agent may reach and return.

I was at Napster when an industry met a new technology. It ignored the thing, shamed the people using it, then asked for rules. This week ran the other way. Money and products showed up ahead of the mandate. That is proactive governance doing its job. It is the same instinct behind the Open Secure AI Alliance.

The part no vendor can sell you

Buying the tools is the easy part. Every find forces a call. An agent turns up with access to customer records and no owner. Someone has to decide today whether it keeps running or goes dark.

Tools can count your agents. Only a person can decide which ones stay.

That work sits Above the Algorithm. Judgment, trust, accountability, and who orchestrates the agents. No vendor sells it. No dashboard closes it for you.

If you do not hold the budget, this still belongs to you. You are probably using an agent nobody above you approved. Write down what it touches. Bring that to your manager this week. Most managers would rather have the list than the surprise.

Multiply that one call across a few thousand firms. It settles things no board votes on. Whether AI shows up at work as something people trust, or as something frozen after the first bad week. Whether that analyst spends next year on cleanup or on the job she was hired for. Whether a customer ever learns what data trained the system that priced her loan.

So take one question into your next leadership meeting. If someone asked today for every AI agent running here, and the data behind each one, how long would we need, and who would we ask? Finding out costs nothing. And if you see it differently, I'm easy to find.

Sources: Snyk, State of Agentic AI Adoption Volume II, August 5, 2026, covering 3,044 enterprises and 1.39 million code repositories, via Help Net Security, IT Pro, and GovInfoSecurity. Zenity Series C, August 3, 2026. Snyk Evo, Airlock Digital, Drata, and Redpanda announcements, August 4, 2026. Black Hat USA 2026 coverage, SecurityWeek and CSO Online.

What is the AI agent governance gap?

The AI agent governance gap is the space between the AI a firm thinks it runs and the AI it really runs. Snyk measured it in August 2026 across 3,044 firms. The real AI footprint came in about 3 times larger than the model lists firms keep. Roughly 50% could not trace a running model back to the data that trained it. Closing the gap starts with finding every agent. Then each one needs an owner.

Here is what makes Alex a credible voice on this topic: Alex Goryachev spent 20 years at Cisco, where he shaped a $1.1B innovation portfolio, and now helps enterprise boards get the AI house in order before a crisis does it for them.

For more, book a conversation →

← Back to Blog
Head portrait of Alex Goryachev
Alex Goryachev

WSJ-bestselling author · Former Managing Director of Innovation, Cisco · Advisor, CSU AI Working Group · LinkedIn Top AI Voice

Work with Alex

Bring this thinking to your organization

Alex works with executive teams at global enterprises on AI strategy, governance frameworks, and organizational readiness. Available for keynotes, C-suite workshops, and advisory engagements.