What It Means To Secure AI on Your Own Terms: Anaconda Acquires Enkrypt AI Anaconda, a data science platform provider, announced the acquisition of Enkrypt AI, an AI security and safety company, to embed trust into the AI-native development lifecycle. Enkrypt AI's data shows that in the two months before the announcement, it scanned over 268,000 tools across 25,000 MCP servers, finding more than 143,000 vulnerabilities affecting 73% of those servers. The acquisition addresses the growing attack surface as enterprise AI use surges to nearly a trillion tokens per month. Every enterprise can now tell you how fast its AI agents are moving. Fewer can tell you what those agents are actually doing. Picture this: you’re a global enterprise, and one of your engineering teams has just completed a year’s worth of work in under two months, an accomplishment brought by standardizing their workflows around a single frontier AI lab. They delivered the kind of velocity every enterprise is chasing right now and did it at the speed today’s market strives for. However, this also meant they had to standardize on a single frontier lab’s stack, giving the team far less visibility into associated risk. Everything running through these models was, in practice, a black box behind an API. When asked, the engineering team and subsequently the leadership team were not able to confidently say what they had worked on was secure and safe. This anecdote came from one of our customer events and is a true example of what enterprises continue to face. What we are announcing today is our answer to this growing need for AI security that works at the speed enterprise CTOs and CISOs expect. Today, Anaconda is acquiring Enkrypt AI /press/anaconda-acquires-enkrypt-ai , the AI security and safety layer used by enterprises to secure, monitor, and govern their complete AI agent stack, embedding trust more deeply into the AI-native development lifecycle. The Trillion-Token Attack Surface As enterprise AI use continues to surge up to nearly a trillion tokens per month , CTOs are counting on agents to make their teams faster and more competitive. At the same time, CISOs are working to ensure safety and security as those same agents become more autonomous. Both things being true and as agents gain more autonomy, the gap between what CTOs want to unleash and what CISOs can safely allow keeps widening. What’s been missing is a systematic way to answer the question every board is now asking: can we trust what our agents are actually doing? Enkrypt AI’s own data found evidence of a compounding issue in agent security. In the two months leading up to this acquisition announcement, Enkrypt AI scanned more than 268,000 tools the individual functions AI agents call across 25,000 MCP servers, and found more than 143,000 vulnerabilities, affecting 73% of those servers. Unlike traditional security risks, you cannot just patch your way out of AI risk. There’s no patch for an exposure that was never fully understood in the first place. Every model an agent runs on, every tool it calls, and every MCP server it touches introduces a potential attack vector. Trust can’t be added after an agent ships. It has to be built into and run on a trusted foundation from day one. This should tell us the growing attack surface is not an abstract thing. It’s real, it’s here, and the vulnerabilities and risks are likely already in flight or have landed in your AI-native workloads. What This Actually Looks Like As AI agents take on more autonomy, the risk scales with what they’re capable of. A manipulated image or document can redirect an agent’s tools without anyone noticing. A spoofed voice input can trigger an approval that was never meant to be given. A single bad instruction, unexamined, can cascade into a wire transfer, an attack on another company https://openai.com/index/hugging-face-model-evaluation-security-incident/ , or a decision no one can later account for in an audit. And what these agents are “actually doing” can be downright sinister. Earlier this month, The Wall Street Journal https://www.wsj.com/tech/ai/openai-chatbot-biological-weapons-poison-3d808e6c reported that a widely used AI chatbot gave detailed responses to user queries about producing dangerous biological and chemical agents, after the underlying model’s safety systems were bypassed. Enkrypt AI’s capabilities are meant for these scenarios, covering the full AI-native security lifecycle: pre-deployment red-teaming across more than 300 attack categories so failures surface in testing rather than in front of a user, runtime guardrails that block jailbreaks and sensitive-data leakage in real time, deployable inside a customer’s own environment, security across the full agent stack, and compliance automation that turns frameworks like the NIST AI Risk Management Framework and the EU AI Act into enforceable guardrails. Enkrypt AI’s offerings help enterprises comply with critical parts of the EU AI Act active as of August 2 , and enforce those requirements as pressures mount to understand how these AI systems are trained and governed. Enkrypt AI makes the unknown known, giving teams the security and governance controls to get the board, CISO, and legal sign-off they need to scale agentic systems with confidence. Further, Enkrypt AI’s research team has red-teamed models across today’s leading frontier AI providers https://app.enkryptai.com/leaderboard such as Anthropic, Mistral, OpenAI, Gemini, and DeepSeek, finding exploitable attack categories in every one. That deep understanding of model behaviors and quick insights are making agents safer, and putting trust back into developer teams as well as enterprise leaders. Faced with all of this, the instinct is to treat speed and safety as a forced choice: move fast and hope, or slow down and govern. Enterprises shouldn’t have to trade away security or compliance to run AI agents at scale. More importantly, enterprises should live in a space where they can define their own guardrails instead of inherited, by-default standards. Whether that’s with open weights models, or when working in highly regulated industries, this is exactly what this acquisition is built to support. Open weights models matter, because they let enterprises define and choose the guardrails that fit their use case. More importantly, enterprises around the world are embracing open weights models /blog/anaconda-open-weights-ai-letter that give them better control over their data, decisions, and actions. These models make it easier to fine-tune their behavior and reasoning patterns. The flexibility is highly desired, but it can also introduce unexpected safety or security issues. To mitigate these concerns, more enterprises have been turning to Enkrypt to ensure speed and safety work at their scale and pace. What We're Building Together For more than a decade, Anaconda has been curating and securing the open source packages and models AI teams depend on. Production-grade AI orchestration /press/anaconda-acquires-outerbounds is now built directly into the platform, giving teams a governed path from experimentation to production. Anaconda’s recent acquisition of Kilo Code /press/anaconda-acquires-kilo-code extended that foundation into the agentic engineering environments, meeting builders right where they work. Now, Enkrypt AI brings the security, governance, and compliance layer that sits across all of it: testing models, agents, and MCP servers before they ship, protecting agents at runtime, and producing the audit trail security and compliance teams need. The best agents and products are the ones where customers never have to think about security or risk at all. Trust is built in from the start, so customers can focus on the value they are creating. This is the next phase of Anaconda’s journey. The Anaconda Platform now lets enterprises discover, build, deliver, observe, and secure AI at trillion-token scale, on a single, trusted platform. Any agent a customer builds on top of in the Anaconda Platform has that security and safety layer built into it. Every model, agent, and MCP server along the way becomes one the enterprise can actually trust. This is what AI on your own terms can become. For AI and platform teams: you can move at the pace of the engineering team in our opening story, without inheriting their blind spot. Every model, agent, and MCP server you ship has a governed path to validation, with runtime guardrails that work inside your own environment rather than requiring everything to route through the public cloud. For security and compliance leaders: the frameworks you already answer to—the NIST AI Risk Management Framework, the EU AI Act, and the industry-specific rules layered on top—become enforced, automated controls instead of a manual audit exercise you’re always chasing. The wire transfer or account change an ungoverned agent might trigger becomes one your audit trail can actually explain, not a headline you find out about after the fact. The Anaconda Platform Story Continues Anaconda’s platform is being built to cover the full AI-native development lifecycle: the governed foundation where AI development begins, AI orchestration that enables AI-native workloads to run reliably at scale, the agentic engineering layer with Kilo where builders and agents do the work, and now, with Enkrypt AI, the security and guardrails that make sure all of it can be trusted. AI that is capable, but without the proper safety and security measures, is a liability. AI that is governed at a slow pace sees the market move on without them. The only platform worth deploying at enterprise scale is one that is fast, capable, secure, and trusted. At trillion-token scale, and beyond it. Contact our team /lp/anaconda-acquires-enkrypt-ai to learn how to build safely and securely with the Anaconda Platform, or read the full announcement /press/anaconda-acquires-enkrypt-ai for more on today’s news. David DeSanto is CEO of Anaconda. Sahil Agarwal is co-founder and CEO of Enkrypt AI.