Anaconda's third acquisition in four months turns a governance story into a security one. The number that matters is not the deal, it's the 73 percent.
Every enterprise can tell you how fast its AI agents are moving. Almost none can tell you what those agents are actually doing, and Enkrypt AI just put a number on that blind spot. In the two months before today's acquisition announcement, Enkrypt scanned more than 268,000 individual tools across 25,000 Model Context Protocol servers and found upwards of 143,000 vulnerabilities, touching 73 percent of the servers it looked at. That statistic, not the deal terms, is the actual news. Anaconda is simply the company that decided to own the fix.
The Third Deal in Four Months
I wrote about Anaconda's acquisition of Outerbounds back in April, when the question was whether the company's governance perimeter could actually stretch from package management into production orchestration. That question has been answered faster than I expected, and with more pieces than I expected. Three weeks ago, Anaconda acquired Kilo Code, the model-agnostic coding agent used by more than 3 million developers, pulling the perimeter into the IDE itself. Today it's Enkrypt AI, and the perimeter now extends into the one place none of the previous deals touched: the runtime layer where agents actually call tools and talk to other systems.
Line the three up and the shape is deliberate rather than opportunistic. Outerbounds governs how AI workflows move from experimentation to production. Kilo Code governs the environment where builders write the code in the first place. Enkrypt governs what happens once an agent is live and pulling on tools, models, and MCP servers that were never fully vetted. Anaconda now owns a claim on all three stages of the AI-native development lifecycle, which is a bigger bet than any single acquisition would suggest on its own.
There's no patch for an exposure that was never fully understood in the first place.
That line, from the joint announcement by CEO David DeSanto and Enkrypt co-founder Sahil Agarwal, is doing more work than it looks like. Traditional security assumes you can identify a flaw and ship a fix. Enkrypt's pitch, and now Anaconda's pitch, is that the agent stack does not work that way. Every model an agent calls, every tool it invokes, every MCP server it touches is a fresh attack surface that did not exist a year ago and that nobody has fully mapped. You cannot patch what you never inventoried.
Why Open Weights Needed This Piece
Anaconda has spent the summer building a public argument for open weight models, one it formalized by signing the Microsoft-anchored open weights letter in July. The pitch has always had a gap in it. Open weights give an enterprise the freedom to choose its own guardrails instead of inheriting a single vendor's defaults, but freedom to choose guardrails is only useful if you have guardrails good enough to choose. Enkrypt closes that gap directly. Its research team has already red-teamed frontier models across Anthropic, Mistral, OpenAI, Gemini, and DeepSeek and found exploitable attack categories in every one of them, open weight or not. That is the uncomfortable finding underneath the marketing framing: the choice was never between safe and unsafe models. It was between vetted and unvetted ones.
The timing lines up with something outside Anaconda's control. The EU AI Act became enforceable on August 2, two days before this announcement. Enkrypt's compliance automation, which maps frameworks like the EU AI Act and the NIST AI Risk Management Framework into enforced technical controls, turns a legal deadline into a product feature almost immediately. That is either very good timing or very good planning, and from the outside those look identical.
A Note on How I Got This
I was heads down at Ai4 and Black Hat this week and missed the announcement when it landed. I heard about it from Derek Weeks, Anaconda's CMO, who I know personally. Derek joined Anaconda in April, right around the Outerbounds deal I covered at the time, and his name has come up in my analysis before on its own merits, not because of the friendship. I'm flagging the relationship here because it's relevant, not because it changes the read. The 73 percent figure is the same number whether or not I know anyone at the company that just bought the firm that found it.
Before you take a demo of anything Enkrypt-branded inside the Anaconda Platform, ask your own team a simpler question first: do you know how many MCP servers your agents are currently talking to, and has anyone scanned a single one of them? If the honest answer is no, the acquisition is not the risk. The three months before you get around to answering that question are.
Sources
DeSanto, David, and Sahil Agarwal. "What It Means To Secure AI on Your Own Terms: Anaconda Acquires Enkrypt AI." Anaconda Blog, 4 Aug. 2026, anaconda.com.
"Anaconda Acquires Enkrypt AI." Press Release, 4 Aug. 2026, anaconda.com.
"Enkrypt AI Agent Guardrails." Enkrypt AI, enkryptai.com.
Weeks, Derek E. "Why Anaconda Acquired Outerbounds." LinkedIn Pulse, 29 Apr. 2026, linkedin.com.
"AI on Your Own Terms: Anaconda Acquires Kilo Code." Anaconda Blog, anaconda.com.
Bellamkonda, Shashi. "Anaconda Just Bought the Half of the AI Stack It Never Owned." Shashi.co, 29 Apr. 2026, shashi.co.
