SecurityBrief US - Technology news for CISOs & cybersecurity decision-makers
United States
Snyk Evo lifts deals as AI agent security demand surges

Snyk Evo lifts deals as AI agent security demand surges

Wed, 30th Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Evo now accounts for 60% of Snyk's new deal volume and is lifting average contract value by 30%.

The figures suggest large companies are spending more on tools to monitor and control AI agents as they move from trials into live software development and operations. Since the first part of Evo became generally available in March, customer growth has been running at 81.5% month on month, according to Snyk.

The Boston-based cybersecurity company is positioning Evo as a layer for overseeing AI agents, rather than simply scanning the code they produce. Businesses are adopting the software as they confront a rising number of software vulnerabilities and a broader attack surface created by coding agents, third-party tools and machine-to-machine workflows, it said.

Across Snyk's customer base of more than 4,800 organisations, newly introduced issues rose 108% between the fourth quarter of 2024 and the first quarter of 2026, according to the company. Snyk argues that AI is increasing pressure on security teams by generating more code and more potential flaws than developers can review manually, while also giving attackers faster ways to find weaknesses.

Evo is already in use at some of the largest US companies, including deployments within the Fortune 50, Snyk said. One live deployment is at one of the largest banks in the US, where the software is used to assess and continuously scan an internal registry of about 1,000 agent skills for 50,000 developers using Claude Code.

Installation times have been relatively short, according to Snyk. Of customers that bought Evo in the second quarter, 76% had moved it into production before the quarter ended, a faster timetable than is typical for enterprise security software.

Snyk also disclosed operating figures intended to show the scale of usage. It now processes 2.4 million agent supply-chain scans a month and 4.2 million agent behaviour checks a day across more than 417,000 onboarded machines, it said.

Growing exposure

Snyk argues that AI agents create a different kind of security problem from conventional software development. Agents can pull in external tools, connect to model context protocol servers and take actions in production environments that previously would have required human approval. That means security systems that inspect software artefacts alone may miss how those agents behave at runtime.

Ken MacAskill, chief executive officer of Snyk, said demand reflects a gap between the speed of AI adoption and the ability of security teams to manage the risks.

"Vulnerabilities are compounding faster than teams can clear them, and on top of that, agents add a whole new layer of exposure," said Ken MacAskill, chief executive officer of Snyk. "We are in exactly the right place at the right time. We built Evo long before enterprises knew to ask for it, because the answer was never more AI grading its own homework - it has to be independent validation. Not only is Evo growing rapidly, but more than three-quarters of enterprises who bought Evo deployed it in production within the same quarter. It is clear evidence that enterprises are urgently implementing solutions to address growing agentic AI security risks."

A central theme in Snyk's pitch is that the same AI model should not both generate code and judge whether that code or an agent's actions are safe. Its approach uses what it describes as an independent validation layer to review tools, code, fixes and agent behaviour.

Snyk said this design improves the rate at which remediation work is accepted. Open-source issues remediated through its validation layer merge at a 94% higher rate than fixes produced by a frontier model working alone, according to the company.

Product scope

Evo is structured around several product areas. These include tools for agentic application security, software for governing agent-led development processes, an AI security posture management offering that tracks models, agents and AI applications across an organisation, and a continuous offensive security product that tests whether policies and controls can be bypassed.

Manoj Nair, chief technology officer of Snyk, said companies are seeing a predictable pattern as they roll out coding agents and AI applications.

"The sequence is predictable," said Manoj Nair, chief technology officer of Snyk. "An enterprise introduces coding agents. Then it ships its own AI applications. Then it finds that attackers are probing both at machine speed, chaining the low-severity issues the old model told teams to ignore. Each step adds a surface the previous generation of tooling was never built to see. Evo covers the development loop, the production loop and the adversarial loop, because a loop with a missing segment is not a loop. It is a gap an autonomous attacker will occupy."

Snyk's own research into large language model consistency underpins part of that argument. Tests using the same code and prompt five times found that nearly half of the issues flagged by a language model alone appeared in only one of the five runs, while the best-performing model in the test scored 75.4% against Snyk's reference set, according to the company.

Customers are also describing risk from the wider toolchain around AI agents, rather than from generated code alone.

"We're seeing supply-chain attacks, malicious skills and compromised MCP servers enter through the agent's own toolchain, alongside agents taking actions with no guardrails between intent and execution," said Brendan Putek, director of DevOps at Relay Network. "Working with Snyk, we landed on what I believe is the right architecture for agentic development security: controls embedded directly into the agent workflow that govern what an agent uses, executes and generates."