{"id":208533,"date":"2026-03-24T19:15:35","date_gmt":"2026-03-24T18:15:35","guid":{"rendered":"https:\/\/liora.io\/en\/snyk-agent-security-evo-ai-spm-governance"},"modified":"2026-08-09T18:34:05","modified_gmt":"2026-08-09T17:34:05","slug":"snyk-agent-security-evo-ai-spm-governance","status":"publish","type":"post","link":"https:\/\/liora.io\/en\/snyk-agent-security-evo-ai-spm-governance","title":{"rendered":"Snyk Agent Security, Evo AI-SPM disrupt AI governance"},"content":{"rendered":"\n<p><strong>\nSecurity firm Snyk launched Agent Security on Monday, a platform designed to protect companies from ungoverned AI agents that pose cybersecurity risks. The solution monitors and controls autonomous AI systems from development through deployment, addressing the growing <a href=\"https:\/\/liora.io\/en\/all-about-shadow-ai\">&#8220;Shadow AI&#8221; problem<\/a> where unauthorized AI components operate without oversight. The platform includes Snyk&#8217;s newly released Evo AI-SPM engine for scanning, validating and enforcing security policies on AI-generated code.\n<\/strong><\/p>\n\n\n<p>The new platform arrives as enterprises grapple with ungoverned AI components that bypass traditional security controls. During its early access period, <strong>over 500 Evo scans<\/strong> uncovered AI elements that had slipped past existing cloud security stacks, according to Snyk. The company reports that <strong>Snyk Studio<\/strong> is already deployed across more than <strong>300 enterprise customers<\/strong> supporting AI coding tools including Claude Code, Cursor, and Devin.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"three-step-security-framework\">Three-Step Security Framework<\/h2>\n\n\n<p><strong>Snyk<\/strong> defines Agent Security as a unified strategy to govern AI agents throughout their entire lifecycle, from code to runtime. The solution operates through three core steps: providing visibility into AI components, delivering intelligence on associated risks, and enforcing policies to block unsafe configurations before production deployment.<\/p>\n\n\n<p>The platform includes <strong>Agent Scan<\/strong>, now in open preview, which discovers and assesses risks in AI agent components such as Model-as-a-Service providers, plugins, and external tools. <strong>Agent Guard<\/strong>, currently in private preview, monitors agent behavior during development and provides real-time policy enforcement with the ability to block unsafe actions as they occur. <strong>Agent Red Teaming<\/strong>, also in open preview, proactively identifies vulnerabilities by simulating multi-step attack scenarios including prompt injection and data exfiltration.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"evo-ai-spm-engine-powers-detection\">Evo AI-SPM Engine Powers Detection<\/h2>\n\n\n<figure class=\"wp-block-image size-full\" style=\"margin-top:32px;margin-bottom:32px\"><img alt=\"Screenshot of the Snyk Agent Security dashboard showing the Evo AI-SPM interface with policy details and status updates.\" class=\"wp-image-208524\" decoding=\"async\" height=\"572\" loading=\"lazy\" sizes=\"(max-width: 1024px) 100vw, 1024px\" src=\"https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-1024x572.jpg\" srcset=\"https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-56x56.jpg 56w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-115x64.jpg 115w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-150x150.jpg 150w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-210x117.jpg 210w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-300x167.jpg 300w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-410x270.jpg 410w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-440x246.jpg 440w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-448x448.jpg 448w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-587x510.jpg 587w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-768x429.jpg 768w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-785x438.jpg 785w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-1024x572.jpg 1024w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-1250x590.jpg 1250w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-1440x680.jpg 1440w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-1536x857.jpg 1536w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-2048x1143.jpg 2048w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-scaled.jpg 2560w\" style=\"width:100%;height:auto\" width=\"1024\"\/><\/figure>\n\n\n<p><strong>Evo AI-SPM<\/strong>, which moved from stealth to general availability on Monday, serves as the central engine for the Agent Security solution. Its code-first architecture focuses on identifying AI components as they enter software development rather than after deployment.<\/p>\n\n\n<p>The engine employs specialized automated agents: a <strong>Discovery Agent<\/strong> that scans codebases to generate a live AI Bill of Materials (AI-BOM), a <strong>Risk Intelligence Agent<\/strong> that enriches this inventory with security metadata and metrics on issues like hallucinations and bias, and a <strong>Policy Agent<\/strong> that translates plain-language governance policies into machine-enforceable controls within CI\/CD pipelines.<\/p>\n\n\n<p>&#8220;Agentic architectures turn governance into a software supply chain problem,&#8221; said <strong>Manoj Nair<\/strong>, Snyk&#8217;s Chief Innovation Officer, positioning the solution as distinct from <a href=\"https:\/\/liora.io\/en\/cloudflare-ai-security-enterprise-shift\">cloud security platforms<\/a> that typically monitor AI assets only after deployment.<\/p>\n\n\n<p><strong>WEX<\/strong> highlighted Evo AI-SPM&#8217;s ability to provide &#8220;full visibility&#8221; into a company&#8217;s AI landscape quickly, according to testimonials shared by Snyk. The phased rollout, with some components still in preview, suggests ongoing enterprise collaboration to refine the platform&#8217;s capabilities.<\/p>\n\n\n<h3 class=\"wp-block-heading\" id=\"sources\">\n    Sources\n  <\/h3>\n\n\n<ul class=\"wp-block-list\">\n<li>snyk.io\/news<\/li><li>securityboulevard.com<\/li>\n<\/ul>\n\n","protected":false},"excerpt":{"rendered":"<p>Security firm Snyk launched Agent Security on Monday, a platform designed to protect companies from ungoverned AI agents that pose cybersecurity risks. The solution monitors and controls autonomous AI systems from development through deployment, addressing the growing &#8220;Shadow AI&#8221; problem where unauthorized AI components operate without oversight. The platform includes Snyk&#8217;s newly released Evo AI-SPM engine for scanning, validating and enforcing security policies on AI-generated code.<\/p>\n","protected":false},"author":87,"featured_media":208527,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"editor_notices":[],"footnotes":""},"categories":[2417],"class_list":["post-208533","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"_links":{"self":[{"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/posts\/208533","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/users\/87"}],"replies":[{"embeddable":true,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/comments?post=208533"}],"version-history":[{"count":1,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/posts\/208533\/revisions"}],"predecessor-version":[{"id":210885,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/posts\/208533\/revisions\/210885"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/media\/208527"}],"wp:attachment":[{"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/media?parent=208533"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/categories?post=208533"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}