# What happened
# Why it matters Enterprises are deploying coding agents and other agentic AI that generate code, pull third-party skills, and act at runtime. Snyk's customer data shows newly introduced issues climbed 108% between Q4 2025 and Q1 2026. That rise, combined with attackers probing at machine speed, creates a backlog of vulnerabilities developers cannot clear with traditional tools designed to scan static artifacts.
# How Evo works Snyk positions Evo on one principle: the generator cannot validate itself. Evo adds an independent, deterministic security layer beneath models. It is multi-model by design and runs three types of checks across the development and production lifecycles:
- Agent supply-chain scans (Snyk reports 2.4 million scans per month).
- Agent behavior checks (4.2 million checks per day across onboarded repositories).
- Continuous scanning integrated into existing workflows and registries.
Evo's product lineup addresses three linked problems: untrusted agentic development, ungoverned AI applications, and automated AI attacks. Offerings include Secrets Detection (generally available), the Remediation Agent (open preview), and an Agentic AppSec Agent (private preview) that aims to automate triage and remediation loops.
# Deployment outcomes and customer traction Snyk reports rapid time-to-live: 76% of customers who bought Evo in Q2 installed it and ran it in production before quarter-end. Evo is deployed at scale across more than 417,000 onboarded repositories and reaches into the Fortune 50. One large U.S. bank centralized roughly 1,000 internal agent skills for 50,000 developers and uses Snyk for pre-registry risk assessment and continuous scanning of that skills registry.
# Measurable impacts Snyk's data points emphasize two outcomes:
- Fixes validated through Snyk's independent layer merge at a 94% higher rate than fixes produced by a single frontier model.
Snyk argues these results show the need for deterministic validation and application context rather than sole reliance on a single model grading its own output.
# Practical takeaways for security and engineering leaders
- Treat agentic AI as production software with continuous security controls, not a temporary experiment. Snyk says enterprises are already moving in that direction.
- Add independent validation under model outputs to reduce noisy, inconsistent findings and improve remediation rates.
- Integrate runtime behavior checks and supply-chain scans for agent skills and external servers the agent may pull at runtime.
# What Snyk's leadership says Snyk CEO Ken MacAskill: "We built Evo long before enterprises knew to ask for it because the answer was never about more AI grading its own homework — it has to be independent validation."
Snyk CTO Manoj Nair: "An enterprise introduces coding agents and ships its own AI applications. Then it finds that attackers are probing both at machine speed, chaining the low-severity issues the old model told teams to ignore. Evo covers the development loop, the production loop and the adversarial loop."