{"id":208533,"date":"2026-03-24T19:15:35","date_gmt":"2026-03-24T18:15:35","guid":{"rendered":"https:\/\/liora.io\/en\/snyk-agent-security-evo-ai-spm-governance"},"modified":"2026-03-24T19:15:35","modified_gmt":"2026-03-24T18:15:35","slug":"snyk-agent-security-evo-ai-spm-governance","status":"publish","type":"post","link":"https:\/\/liora.io\/en\/snyk-agent-security-evo-ai-spm-governance","title":{"rendered":"Snyk Agent Security, Evo AI-SPM disrupt AI governance"},"content":{"rendered":"<p><strong>\nSecurity firm Snyk launched Agent Security on Monday, a platform designed to protect companies from ungoverned AI agents that pose cybersecurity risks. The solution monitors and controls autonomous AI systems from development through deployment, addressing the growing <a href=\"https:\/\/liora.io\/en\/all-about-shadow-ai\">&#8220;Shadow AI&#8221; problem<\/a> where unauthorized AI components operate without oversight. The platform includes Snyk&#8217;s newly released Evo AI-SPM engine for scanning, validating and enforcing security policies on AI-generated code.\n<\/strong><\/p>\n<p>The new platform arrives as enterprises grapple with ungoverned AI components that bypass traditional security controls. During its early access period, <b>over 500 Evo scans<\/b> uncovered AI elements that had slipped past existing cloud security stacks, according to Snyk. The company reports that <b>Snyk Studio<\/b> is already deployed across more than <b>300 enterprise customers<\/b> supporting AI coding tools including Claude Code, Cursor, and Devin.<\/p>\n\n<h2 style=\"margin-top:2rem;margin-bottom:1rem;\">Three-Step Security Framework<\/h2>\n\n<p><b>Snyk<\/b> defines Agent Security as a unified strategy to govern AI agents throughout their entire lifecycle, from code to runtime. The solution operates through three core steps: providing visibility into AI components, delivering intelligence on associated risks, and enforcing policies to block unsafe configurations before production deployment.<\/p><br><p>The platform includes <b>Agent Scan<\/b>, now in open preview, which discovers and assesses risks in AI agent components such as Model-as-a-Service providers, plugins, and external tools. <b>Agent Guard<\/b>, currently in private preview, monitors agent behavior during development and provides real-time policy enforcement with the ability to block unsafe actions as they occur. <b>Agent Red Teaming<\/b>, also in open preview, proactively identifies vulnerabilities by simulating multi-step attack scenarios including prompt injection and data exfiltration.<\/p>\n\n<h2 style=\"margin-top:2rem;margin-bottom:1rem;\">Evo AI-SPM Engine Powers Detection<\/h2><figure class=\"wp-block-image size-large\" style=\"margin-top:var(--wp--preset--spacing--columns);margin-bottom:var(--wp--preset--spacing--columns)\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"572\" src=\"https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-1024x572.jpg\" alt=\"Screenshot of the Snyk Agent Security dashboard showing the Evo AI-SPM interface with policy details and status updates.\" class=\"wp-image-208524\" srcset=\"https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-56x56.jpg 56w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-115x64.jpg 115w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-150x150.jpg 150w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-210x117.jpg 210w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-300x167.jpg 300w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-410x270.jpg 410w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-440x246.jpg 440w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-448x448.jpg 448w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-587x510.jpg 587w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-768x429.jpg 768w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-785x438.jpg 785w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-1024x572.jpg 1024w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-1250x590.jpg 1250w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-1440x680.jpg 1440w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-1536x857.jpg 1536w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-2048x1143.jpg 2048w, https:\/\/liora.io\/app\/uploads\/sites\/9\/2026\/03\/snyk-agent-security-evo-ai-spm-dashboard-scaled.jpg 2560w\" sizes=\"(max-width: 1024px) 100vw, 1024px\"><\/figure>\n\n<p><b>Evo AI-SPM<\/b>, which moved from stealth to general availability on Monday, serves as the central engine for the Agent Security solution. Its code-first architecture focuses on identifying AI components as they enter software development rather than after deployment.<\/p><br><p>The engine employs specialized automated agents: a <b>Discovery Agent<\/b> that scans codebases to generate a live AI Bill of Materials (AI-BOM), a <b>Risk Intelligence Agent<\/b> that enriches this inventory with security metadata and metrics on issues like hallucinations and bias, and a <b>Policy Agent<\/b> that translates plain-language governance policies into machine-enforceable controls within CI\/CD pipelines.<\/p><br><p>&#8220;Agentic architectures turn governance into a software supply chain problem,&#8221; said <b>Manoj Nair<\/b>, Snyk&#8217;s Chief Innovation Officer, positioning the solution as distinct from <a href=\"https:\/\/liora.io\/en\/cloudflare-ai-security-enterprise-shift\">cloud security platforms<\/a> that typically monitor AI assets only after deployment.<\/p><br><p><b>WEX<\/b> highlighted Evo AI-SPM&#8217;s ability to provide &#8220;full visibility&#8221; into a company&#8217;s AI landscape quickly, according to testimonials shared by Snyk. The phased rollout, with some components still in preview, suggests ongoing enterprise collaboration to refine the platform&#8217;s capabilities.<\/p>\n<div style=\"margin-top:3rem;padding-top:1.5rem;border-top:1px solid #e2e4ea;\">\n  <h3 style=\"margin:0 0 0.75rem;font-size:1.1rem;letter-spacing:0.08em;text-transform:uppercase;\">\n    Sources\n  <\/h3>\n  <ul style=\"margin:0;padding-left:1.2rem;list-style:disc;\">\n    <li>snyk.io\/news<\/li><li>securityboulevard.com<\/li>\n  <\/ul>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Security firm Snyk launched Agent Security on Monday, a platform designed to protect companies from ungoverned AI agents that pose cybersecurity risks. The solution monitors and controls autonomous AI systems from development through deployment, addressing the growing &#8220;Shadow AI&#8221; problem where unauthorized AI components operate without oversight. The platform includes Snyk&#8217;s newly released Evo AI-SPM engine for scanning, validating and enforcing security policies on AI-generated code.<\/p>\n","protected":false},"author":87,"featured_media":208527,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"editor_notices":[],"footnotes":""},"categories":[2417],"class_list":["post-208533","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"_links":{"self":[{"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/posts\/208533","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/users\/87"}],"replies":[{"embeddable":true,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/comments?post=208533"}],"version-history":[{"count":0,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/posts\/208533\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/media\/208527"}],"wp:attachment":[{"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/media?parent=208533"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/categories?post=208533"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}