Anaconda Bought Your AI Red Teamer. Read the License.

Anaconda acquired Enkrypt AI on August 4 for undisclosed terms, putting the red-teaming vendor you chose for its neutrality inside a platform company. The bigger exposure is the license: Anaconda spent 2024 and 2025 enforcing a 200-employee 'free' threshold with demand letters that threatened back bills, and Enkrypt's $0 and $149 self-serve tiers now belong to it.

By Rajesh Beri·August 4, 2026·11 min read
Share:
A printed AI red-team assessment report on a desk, its cover page stamped with a fresh corporate ownership stamp, beside an open laptop showing a subscription pricing card and a paper invoice envelope. No text or logos l

Illustration generated using AI

You did not buy Enkrypt AI because it had the best jailbreak detector. You bought it because it did not sell you the thing it was grading. That was the whole product. On August 4, 2026, Anaconda acquired Enkrypt AI for undisclosed terms, and the assessor is now owned by a company selling an AI development platform.

Two exposures landed on your desk in the same press release, and neither one is in the announcement. The first is evidentiary: every red-team scorecard, model comparison and EU AI Act artifact you generated with Enkrypt was worth something because the assessor had no platform to sell. The second is contractual, and it is the one nobody is looking at — Enkrypt's free and $149-a-month self-serve tiers now belong to the company that spent 2024 and 2025 reinterpreting the word "free" and sending demand letters to enforce the new reading.


What Anaconda Actually Bought

Anaconda bought the assessment layer that sits above every model and MCP server an enterprise runs — the part that produces evidence, not the part that produces output.

Enkrypt AI's platform does pre-deployment red teaming across 300 AI risk subtypes in six categories, runtime guardrails, an agent policy engine that compiles regulation into enforceable rules, and an MCP scanner and gateway. Anaconda's announcement puts the red-teaming coverage at 300+ attack categories with compliance automation mapped to the NIST AI Risk Management Framework and the EU AI Act. The customer logos on Enkrypt's own site are the reason this matters beyond the cap table: AI21 Labs, NATO StratCom COE, Skyhigh Security, NetApp and Salesforce.

The work is real and it is checkable. In October 2025 Enkrypt published research on 1,000 MCP servers — "the top 1,000 in the ecosystem," by its own description — that found 32% carried at least one critical vulnerability, at 5.2 vulnerabilities per server: authorization bypass in 41% of them, prompt injection paths in 35%, command injection in 28%. Read it with the interest stated, which is the same test this article is applying to everything else — it was produced by the company selling the MCP scanner, against the most-used servers rather than a random sample. It remains the widest public measurement of that attack surface, and it is the reason a lot of security teams bought the scanner in the first place.

Then there is the artifact with the longest half-life: the LLM Safety Leaderboard, which benchmarks 200+ frontier models on jailbreak susceptibility, bias, malware and toxicity, and describes itself as "independent rankings." Enterprises have been pasting those scores into model-selection memos for two years.

The Independence Was the Product, and It Just Changed Hands

An independent assessor is one with no commercial position in the thing it assesses. Anaconda now has one, so Enkrypt's output is no longer independent in that sense — regardless of how good the engineering stays.

Steel-man the other side first, because it is a decent argument. Anaconda does not build frontier models. It has no Claude, no GPT, no Gemini to protect, so the leaderboard's rankings of Anthropic, Mistral, OpenAI, Gemini and DeepSeek face no obvious pressure. Anaconda has also been explicit about neutrality elsewhere: when it bought Kilo Code on July 15, 2026, it described the model gateway as "flexible, and anti–lock-in" across 500+ models and confirmed "Kilo remains available for individual builders, teams, and organizations." That is a real commitment, made in public, about a comparable product.

Here is where the argument stops. Anaconda does not sell models, but it sells the platform the agents are built on — and Enkrypt does not only grade models. It grades MCP servers, agent stacks and deployments, which is precisely what the Anaconda Platform now produces. The announcement, co-authored by Anaconda CEO David DeSanto and Enkrypt CEO Sahil Agarwal, frames the deal as foundational rather than adjacent: "Trust can't be added after an agent ships. It has to be built into and run on a trusted foundation from day one." Read that as a buyer. A scanner owned by the platform vendor, scanning agents built on that platform, is not the same instrument it was on August 3.

This is now the default outcome in AI security, not an aberration. Check Point announced its acquisition of Lakera on September 16, 2025, folding the red-teaming and runtime-protection vendor into a Global Center of Excellence for AI Security; co-founder David Haber's line was "Joining Check Point allows us to accelerate and scale our mission globally." Good for the mission. The pure-play bench that CISOs used to triangulate against their platform vendors keeps getting shorter, and the Anaconda deal follows Outerbounds in April 2026 and Kilo Code in July — three acquisitions in roughly three months, assembling one stack.

Anaconda Has a Documented History With the Word "Free"

This is the part a wire report will not carry, and it is the reason to open your Enkrypt contract this week rather than next quarter.

Anaconda's current pricing page states the rule plainly: "Users within organizations with 200+ employees/contractors (including Affiliates) require a paid Business license" — Business being $50 per user per month, against a $0 Free tier and a $15 Starter tier. That threshold is not new. What matters is how it arrived and how it was enforced.

The Register's August 2024 account tracks the drift: fees for "heavy commercial use" in April 2020, a clarification in October 2020 that the 200-employee line applied to organizations while promising Anaconda would "always offer a free version for academics, hobbyists, non-profits, and small businesses" — and then, by May 2023, the language exempting academic and non-profit organizations quietly disappearing from the terms. By March 2024 the terms required government and non-profit entities with over 200 employees or contractors to pay. Mass General Brigham told its researchers they had until August 31 to obtain licenses, saying it "was only alerted to this issue in early 2024." One non-profit research institution received a demand warning that Anaconda's "legal team may be compelled to consider measures aligned with our prevailing pricing and invoicing policies, which could include issuing back bills for any unauthorized or excess usage."

Back bills. For software a large organization believed it had been invited to use for free.

Then the letters became lawsuits. Anaconda sued Intel on August 8, 2024, alleging Intel kept using its software after the license expired and shipped it inside Intel's own AI toolkit — the complaint says Intel "intentionally leveraged Anaconda's technological innovations to improve Intel's own products" in the AI market. Anaconda sued Dell that December. Two others pre-empted it from the opposite direction, suing Anaconda for declaratory judgment: Alibaba Cloud in September 2024 and Airbus in February 2025. Per Airbus's filing, Anaconda's demand letters have ranged "between six- and eight-figures."

To be precise about what is and is not established: Anaconda has made no announcement about Enkrypt's pricing, and none of this history has been applied to an Enkrypt product. It may never be. But you are now buying an assessment tool from a vendor whose distinguishing commercial behavior is retroactive entitlement enforcement, and that changes what belongs in your contract rather than what belongs in your threat model.


The Free Tier Is the Exposure Nobody Has Counted

Enkrypt's self-serve tiers are how it got inside your company without a purchase order, which is exactly why they are the risk.

Enkrypt's pricing is live and unchanged as of today: Explore at $0/month with 500 credits to start and 50 credits monthly, no credit card required; Launch at $149/month ($134 billed annually), which is where MCP server scanning, PII detection, custom policy guardrails and the OWASP/NIST/EU AI Act compliance features actually begin; Scale at $1,499/month for multi-modal red teaming, SSO and CI/CD release gating; and Enterprise at custom pricing for RBAC, VPC and on-prem.

Look at where the line sits. Everything a regulated enterprise needs — compliance mapping, audit logs, MCP scanning — starts at $149 a month, which is under almost every signature threshold in existence. That is a tool that spreads by engineer, not by procurement. If four teams each expensed Launch, your organization has four contracts, no owner, and no record in the vendor master. Anaconda's own 200-employee rule is a per-organization test, "including Affiliates" — that is the shape of policy that turns distributed self-serve adoption into one consolidated bill.

You cannot negotiate what you have not inventoried. Find the credit cards first.

Can You Still Cite the Scorecard?

Yes — with an added line in your documentation naming the ownership, and with a second source for anything load-bearing.

EU AI Act Article 55(1)(a) requires providers of general-purpose AI models with systemic risk to "perform model evaluation in accordance with standardised protocols and tools reflecting the state of the art, including conducting and documenting adversarial testing of the model with a view to identifying and mitigating systemic risks." The Article does not mandate a third-party evaluator, and nothing in it invalidates an Enkrypt result. Most enterprise readers here are deployers, not GPAI providers, and are working the Article 50 transparency obligations rather than Article 55 anyway.

The problem is narrower and more practical. If your model-selection memo, your vendor risk file or your board deck leans on a score to justify choosing one model over another, and the assessor now belongs to a platform vendor whose own agent stack is in scope for the same tool, an auditor will ask. Answering that question in advance costs a sentence. Answering it eighteen months later, in front of a regulator, costs a re-test.

The durable fix is the one that was always correct: never let one vendor be your sole source of adversarial evidence. Run at least one open-source suite alongside the commercial one — Microsoft's RAMPART and PyRIT tooling exists for this, costs nothing, and produces artifacts nobody owns. If you need a commercial second opinion, Lakera is now inside Check Point, which is fine as a cross-check precisely because it is a different platform's captive. Two captives with opposed interests beat one.

What to Do Before This Renews

This Week:

  1. Pull the credit-card statements, not the vendor master. Search expense reports for "Enkrypt" and for $149 and $134 charges. Every self-serve subscription is a contract your legal team has never read.
  2. Export everything. Explore retains data 7 days, Launch 30, Scale 90, per the pricing page. Your red-team results and audit logs are evidence with a short shelf life and no guarantee they survive a platform migration. Get them into your own storage.
  3. Snapshot the leaderboard scores you have cited. If a model comparison in a live document points at a hosted page, capture the version and date you actually relied on.

Before Renewal:

  1. Ask for three things in writing: continuity, neutrality, and price. That the standalone product remains purchasable without an Anaconda Platform subscription; that assessment coverage of non-Anaconda stacks is not deprioritized; and a capped renewal uplift with a defined term. Anaconda made an explicit "remains available" commitment about Kilo Code — ask for the same sentence about Enkrypt, on your paper.
  2. Get an entitlement letter covering your free and self-serve usage to date. Not a promise about the future — a written acknowledgment that usage under the published tiers, at your actual headcount, was licensed. That is the specific document that answers a back-bill demand before it arrives.
  3. Add the change-of-control clause you should have had. Termination for convenience on acquisition, data export in a documented format, and price protection through the term. Three separate acquisitions hit enterprise AI stacks this week alone — the same clause would have helped buyers of Wallaroo, Anyscale and Tabnine.

This Quarter:

  1. Stand up a second, non-commercial adversarial suite and run it against your two highest-risk agents. If the results diverge materially from your commercial scanner, you have learned something worth far more than the license fee.
  2. Re-run your MCP inventory against Enkrypt's 41% authorization-bypass finding. Whatever happens to the vendor, the MCP attack surface is not going anywhere, and agentjacking through poisoned tool outputs is a live technique.

The Bottom Line

Every enterprise software cycle ends the same way: the independent measurement layer gets absorbed by the thing it was measuring. Ratings agencies got paid by issuers. Cloud security posture management got bought by the clouds. AI assurance is running the same play at speed — Lakera into Check Point, Enkrypt into Anaconda, with the pure-play bench thinning every quarter while the category of failures they were built to catch keeps growing.

You cannot stop the consolidation. You can refuse to hold your only copy of the evidence inside it, and you can decline to let a $149 line item become an eight-figure letter.

Independence is not a feature you buy. It is a position you maintain — and it survives exactly as long as you keep a second opinion you did not have to ask permission for.

Continue Reading

How to Red-Team Your AI Agents Before Production Okta Bought Permiso. Your Leverage Expires Oct 31. Tricentis Bought Tabnine's Context Engine, Not Your IDE d-Matrix Bought Wallaroo. Get 'Any Hardware' in Writing. RAMPART: Microsoft's Free Test Suite for $5.7M AI Breaches MCP Goes Stateless: Enterprise AI Governance Just Got Real $60B Bought Cursor. Your Dev Team Is the Product Now. 10,000 AI Failures Exposed. Hallucination Isn't #1.

Share:

Frequently Asked Questions

Who acquired Enkrypt AI and when?

Anaconda acquired Enkrypt AI on August 4, 2026. Terms were not disclosed. It is Anaconda's third acquisition in roughly three months, following Outerbounds in April 2026 and Kilo Code in July 2026, assembling an end-to-end AI-native development platform.

Does the Anaconda acquisition make Enkrypt's red-team scores unusable as evidence?

No. The engineering does not change on day one, and EU AI Act Article 55(1)(a) requires documented adversarial testing without mandating a third-party evaluator. But the assessor now has a commercial position in the agent stacks it scans, so name the ownership in your documentation and keep a second, independent source for any score a model-selection or vendor-risk decision rests on.

What is Enkrypt AI's pricing?

As of August 2026, per Enkrypt's pricing page: Explore at $0/month with 500 starting credits and 50 monthly; Launch at $149/month ($134 billed annually), which is where MCP scanning, PII detection and OWASP/NIST/EU AI Act compliance features begin; Scale at $1,499/month adding multi-modal red teaming, SSO and CI/CD gating; and Enterprise at custom pricing for RBAC and VPC or on-prem deployment.

What should we do about our Enkrypt subscription right now?

Search expense reports for self-serve charges rather than trusting the vendor master, since $149/month sits below most signature thresholds. Export red-team results and audit logs, because retention runs 7 to 90 days by tier. Then ask in writing for standalone product continuity, neutrality on non-Anaconda stacks, capped renewal pricing, an entitlement letter covering usage to date, and a change-of-control termination clause.

What did Enkrypt AI's MCP server research find?

In research published in October 2025, Enkrypt scanned 1,000 MCP servers and found 32% carried at least one critical vulnerability, averaging 5.2 vulnerabilities per server. Authorization bypass appeared in 41% of servers, prompt injection paths in 35%, command injection in 28%, network security issues in 23%, path traversal in 19% and resource exhaustion in 15%.

Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe

Latest Articles

View All →