Fifteen days is what a typical penetration test takes. Three hundred fifty is what's left over for attackers to work with, and for applications to keep changing underneath whatever the test found. Snyk used that math to introduce Evo Continuous Offensive Security at Black Hat USA 2026 on August 4, general availability for autonomous, AI-powered pentesting and agent red teaming that runs on a schedule closer to daily than annual (Snyk, 2026).
Evo COS runs the test, then checks its own work. A second, independent layer reviews every finding before it reaches a security team, an answer to the false-positive fatigue that has slowed adoption of earlier automated scanning tools. Snyk paired the launch with a broader view into AI usage across a company's systems, plus general availability for Snyk Secrets, a tool for catching exposed passwords and API keys built on technology from its BitPatrol acquisition (Snyk, 2026).
The Research Snyk Published Explains Why It Built This
Snyk's State of Agentic AI Adoption report landed the same week, drawn from 3,044 enterprise environments and 1.39 million code repositories. Nearly half of organizations already using AI, 46.9%, have moved to AI agents that act on their own, sometimes wired into company data and outside tools rather than kept at arm's length. More than half of that group have built the full setup, agents and the connections that let them reach in (Help Net Security, 2026).
The report's sharper claim is about visibility, not adoption. A system-level count of what enterprises run turns up an AI footprint roughly three times larger than a model inventory alone would show. Security teams counting models are missing most of what is exposed.
That is the gap Evo COS is priced to close.
A scheduled pentest measures a system that has already changed by the time the report ships.
Three Acquisitions Built the Product Snyk Announced This Week
None of what launched at Black Hat started as a Snyk product. DeepCode, a Swiss startup Snyk acquired in 2020, gave Snyk the code-reading technology still at the center of its scanning today. Invariant Labs, another Swiss team acquired in June 2025 less than a year after its founding, brought researchers who were first to document how AI agents can be tricked into leaking data, work that now anchors Snyk's threat research. BitPatrol, the most recent of the three, supplied the technology behind Snyk Secrets, the tool that reached general availability alongside Evo COS this week (Snyk, 2026).
The pattern holds across all three. Snyk buys small, research-heavy teams close to their founding and ships their work as a named feature within a year or two, rather than acquiring revenue.
Continuous Testing Still Needs Someone to Fix What It Finds
Running pentests daily instead of twice a year produces more findings, faster. Nothing about Evo COS's launch addresses whether remediation capacity grows to match. A security team that could not close the backlog from an annual pentest now inherits a continuous one, and the constraint moves from detection to throughput.
Snyk's own adoption numbers suggest the bottleneck will show up first at organizations already running agentic architectures, the 46.9% with the biggest AI footprint and the least system-level visibility into it.
Before adding continuous pentesting to next year's budget, ask your team how many findings from the last scheduled pentest are still open. If that number is not near zero, a faster testing cadence adds volume to a queue that is not moving, not coverage.
Sources
Snyk. "Evo Continuous Offensive Security Is Here." Snyk, 4 Aug. 2026, snyk.io.
Snyk. "Snyk Secrets Is Now Generally Available." Snyk, 4 Aug. 2026, snyk.io.
Snyk. "Snyk Acquires Invariant Labs to Accelerate Agentic AI Security Innovation." Snyk, 24 June 2025, snyk.io.
Help Net Security. "Your Enterprise AI Footprint Is About Three Times Bigger Than Your Model List." Help Net Security, 5 Aug. 2026, helpnetsecurity.com.
Security Boulevard. "Snyk Brings Evo Continuous Offensive Security to General Availability at Black Hat." Security Boulevard, 4 Aug. 2026, securityboulevard.com.
