What lies beneath? The industry already knows.
Docker surveyed 800+ developers, platform engineers and technology leaders about AI agents in the enterprise. Their numbers are below, quoted directly. The answers are ours.
Source: Docker, The State of Agentic AI — a survey of technical practitioners: the leading edge of adoption, not the market average.
The agents are already in your codebase.
Agent Scan finds every place your code calls AI — agent SDKs, model endpoints, exec-on-model-output — so "are we using agents?" becomes a map, not a guess.
AGENT SCAN →Trust needs evidence, not assurances.
CodeDelta's churn numbers are deterministic and reproducible — the same scan gives the same answer on any machine, so auditors can re-derive every figure.
THE EVIDENCE →Know where you're exposed.
Agent Scan flags MCP and SDK call sites, exec-on-model-output and prompt-injection risk in your own source — the places those attacks would land.
SEE THE SIGNALS →Inventory it. Then gate it.
The AI Bill of Materials (native or CycloneDX) inventories every AI touchpoint in a codebase; the policy gate blocks unapproved providers in CI — before the merge, not after the incident.
AI-BOM & POLICY GATE →Know whose models your code talks to.
The BOM's egress and sovereignty signals show which providers your code calls and where the data goes — the compliance questions, answered from source.
EGRESS & SOVEREIGNTY →All survey figures are quoted from Docker's report (direct PDF · report page). Docker is not affiliated with CodeDelta and does not endorse it. CodeDelta figures and behaviour are documented in our papers — including the full-Chromium scan (2 × 43.5M LOC, churn-compared in a single pass) with reproduction hashes.
