Fetching from the wire…
Public story · 2026-08-04 · high
Snyk surveyed 3,000+ enterprise accounts and found real AI infrastructure runs three times what model inventories show, pushing AI-BOM into procurement.
Why now: The jump from 36% to 50% full-stack agentic adoption in six months is what's pushing AI-BOM tooling into procurement conversations.
Security teams see roughly a third of their real AI footprint, per Snyk's new survey of 3,000-plus enterprise accounts. That means agent frameworks, MCP servers, retrieval systems, and vector databases, the layers attackers actually reach, run two-thirds ungoverned by whatever policy tracks the models. The ratio holds across every region Snyk measured.
Full-stack agentic architecture means production systems with orchestration, memory, and tool-calling, not a single model call. Half of organizations run it, up from 36% six months earlier, per the survey. AI-BOM tooling, the inventory layer for that stack, is turning into its own procurement line separate from model governance budgets.
Model governance built around tracking which LLMs a company uses is already behind the actual footprint. The budget line that matters is the AI-BOM, everything downstream of the model call, because that's the two-thirds security teams can't see. Watch whether AI-BOM tooling gets funded as its own procurement category in the next few quarters, or gets folded into existing AppSec budgets and starved.
The jump from 36% to 50% full-stack adoption in six months is what's turning AI-BOM from a nice-to-have into a live procurement conversation.
Each link below shares sources, entities, or timing with this story.
The agent skills supply chain is under coordinated attack. Snyk's ToxicSkills audit found 36% of ClawHub's 3,984 skills contain prompt injection payloads, 13.4% have critical malware, and submission rates exploded 10x to 500+/day. This week alone: CVE-2026-2256 (CVSS 9.1) is a...
This is the most honest thing published about agents this year, and it's from a SaaS blog, not a research lab. SaaStr has been running 20+ AI agents in production for a year, going from 8 or 9 human salespeople to 1.2 humans plus 20 agents. Then they published a post-mortem on...
First major enterprise observability platform to ship a production-grade MCP server. Feeds live logs, metrics, and traces directly into Claude Code, Cursor, Codex, GitHub Copilot, and VS Code. AI coding agents can now investigate production issues using real-time telemetry. MC...
Robinhood unveiled Agentic Trading and an Agentic Credit Card on May 27, letting users connect any MCP-compatible AI agent to autonomously trade stocks and make purchases with 3% cash back. Claude, ChatGPT, Codex, Cursor, anything that speaks MCP can now interact with financia...
xAI launched Grok Build on May 14. With that, every major AI lab now ships a coding agent that lives in your terminal. The competition isn't "can we build one" anymore. That question is settled. The lineup: Anthropic has Claude Code. OpenAI has Codex CLI. Google has Gemini CLI...
Twelve months ago, OpenAI led Anthropic by 41 points in enterprise adoption. Today that gap is 8. Enterprise Technology Research's survey of roughly 500 respondents shows OpenAI dropping from 62% adoption (September 2025) to 56% (March 2026) while Anthropic surged from 21% to...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.