Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Latest AI and industry news. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

News Trending AI News

73% of AI Agent Tools Are Vulnerable: Anaconda Acts

Anaconda acquires Enkrypt AI after scanning 25,000 MCP servers and finding 143,000 vulnerabilities. Here's what it means for business AI deployments.

Enterprise DNA | | via Anaconda Blog
73% of AI Agent Tools Are Vulnerable: Anaconda Acts

If your business is deploying AI agents, this number should get your attention: 73%.

That’s the share of MCP (Model Context Protocol) servers found to have security vulnerabilities, according to an audit by Enkrypt AI. In the two months leading up to Anaconda’s acquisition announcement on August 4, Enkrypt scanned more than 268,000 tools across 25,000 MCP servers and found over 143,000 vulnerabilities.

Anaconda, the company behind the most widely used Python distribution for data science, acquired Enkrypt AI to add a security and governance layer to its growing AI development platform. The acquisition follows Anaconda’s July 2026 purchase of Kilo Code, which brought agentic engineering capabilities to the platform.

Together, these moves tell a clear story about where enterprise AI is heading: building agents is the easy part. Keeping them secure is the hard part.

Why MCP Servers Are the New Attack Surface

MCP (Model Context Protocol) has become the connective tissue of the AI agent ecosystem. It’s the standard that lets AI models talk to external tools: your CRM, your file system, your databases, your APIs. The promise is massive productivity. The risk, it turns out, is equally significant.

Enkrypt’s research found vulnerabilities across attack categories including prompt injection, tool poisoning, data exfiltration pathways, and more. Businesses plugging AI agents into production systems via MCP connections are often doing so with no visibility into what’s happening underneath.

This isn’t a theoretical risk. It’s a live attack surface that most enterprises haven’t started auditing.

What Enkrypt AI Brings to the Table

Enkrypt AI built its platform specifically to address the gap between building AI systems and securing them. The three core capabilities it brings to Anaconda are:

Pre-deployment red-teaming. Before an AI agent or model goes into production, Enkrypt tests it across 300-plus attack categories, surfacing vulnerabilities before they become incidents rather than after.

Runtime guardrails. Once deployed, Enkrypt monitors agent behavior continuously, blocking jailbreaks and preventing data leakage in real time.

Compliance automation. Enkrypt maps AI systems to regulatory frameworks like the NIST AI Risk Management Framework and the EU AI Act. For businesses operating across jurisdictions, this removes the manual work of staying audit-ready.

The Anaconda Platform Play

Anaconda’s acquisition strategy is building toward a full-stack AI development environment. The company started as the default environment for data scientists and researchers. The Kilo Code acquisition added agentic development tooling. Enkrypt AI adds the governance and security layer that enterprise buyers increasingly require before they’ll approve AI projects at scale.

For enterprise IT and procurement teams that have been slow-rolling AI approvals due to security concerns, this kind of integrated security tooling may actually accelerate deployment decisions. “Yes, we’ve run the red-team tests. Yes, we have runtime guardrails. Yes, we’re NIST-compliant” is a very different conversation than “we trust the vendor.”

What This Means for Business

The 73% vulnerability rate isn’t a reason to avoid AI agents. It’s a reason to approach them with the same rigour you’d apply to any software system connecting to your production data.

A few practical implications for businesses deploying or evaluating AI agent systems:

Audit your MCP connections. If your AI agents are connecting to external tools via MCP, understand what’s on the other end. Your AI provider’s security posture only matters if your connection layer is equally secure.

Ask your vendor about red-teaming. Pre-deployment security testing is now table stakes for serious enterprise AI deployments. If your AI vendor can’t speak to this, it’s a gap.

Build for compliance from the start. Retrofitting compliance onto live AI systems is significantly harder than building it in. Frameworks like NIST and the EU AI Act aren’t going away, and building to them from day one saves time later.

Don’t confuse governance with restriction. The right security layer doesn’t slow down your AI investments. It’s what makes the business case for scaling them.

The era of “deploy and see what happens” is over for AI agents. The next phase is governed deployment, and the vendors who build tooling for that phase will have significant competitive advantages.

For data teams and IT leaders evaluating the build-versus-buy decision for AI infrastructure, Anaconda’s platform is worth a closer look. Security-by-default is no longer a differentiator. It’s becoming the baseline.


Enterprise DNA helps businesses build data capability and deploy AI solutions that work in the real world. Learn more about Omni by Enterprise DNA for AI strategy and deployment, or explore EDNA Learn for data and AI upskilling.

Working With Claude field guide cover

Free Resource

Going deeper with Claude?

Get the free 32-page implementation guide for ANZ teams.

No spam. Unsubscribe any time.