An AI system that only answers questions carries one kind of risk. An agent that can query a database, call an API, or push a change to production carries another kind of risk altogether. Two announcements on August 4 show investors and vendors racing to build a security category around the second kind: Anaconda acquired Enkrypt AI, and AI-agent security startup Zenity raised $125 million.
Anaconda folds security into the AI development stack
Anaconda announced the acquisition of Enkrypt AI on August 4, 2026, adding model, agent and Model Context Protocol (MCP) security to a platform already used across the Python and data-science lifecycle. Financial terms were not disclosed. Enkrypt AI runs pre-deployment red-teaming across more than 300 attack categories, real-time runtime guardrails against jailbreaks and data leakage, and compliance automation for frameworks including the NIST AI Risk Management Framework and the EU AI Act. Anaconda said Enkrypt AI’s products, plans and support continue unchanged for existing customers, and described the company as vendor-neutral and cloud-agnostic. Enkrypt is an OpenAI compliance integration partner, and Anaconda said a similar model-agnostic approach for Anthropic is coming.
The deal extends a pattern. Anaconda acquired workflow-orchestration company Outerbounds in April 2026 and has separately added Kilo Code to its portfolio, moving into agentic developer tooling. Packages and environments, orchestration, AI development, and agent and model security now sit inside a single vendor relationship rather than four separate purchasing decisions. Anaconda says 95% of the Fortune 500 and more than 52 million users rely on its platform, a company-reported figure worth noting as such rather than as independently audited market share.
MCP turns data access into a security boundary
Model Context Protocol servers let AI applications and agents connect to tools and external data sources. The connection is the point of MCP, and it is also the exposure. Each new connection can widen an agent’s permissions, its reach into proprietary data, and the surface an attacker can target.
Enkrypt scanned more than 268,000 tools across 25,000 MCP servers in the two months before the acquisition and reported vulnerabilities affecting 73% of them, more than 143,000 in total. Anaconda repeated the figures in its acquisition announcement. Treat them as vendor research from the company that now stands to sell the fix, not as an independently audited census of MCP deployments generally. Even with the caveat noted, the scale of the finding explains why buyers are asking a different question about AI agents than they asked about earlier generations of software: not just what a model says, but what it is allowed to do next.
Zenity’s $125 million says capital is following the control layer
SecurityWeek reported August 4 that Zenity raised $125 million in a Series C round led by Norwest, bringing its total funding to $180 million. Qumra Capital, SoftBank Vision Fund 2, Hitachi Ventures, LG Technology Ventures and existing investors Vertex Ventures, Third Point Ventures, DTCP and Intel Capital also participated. Zenity, founded in 2021, employs more than 230 people and says it has tripled revenue in each of the past two years. CEO Ben Kliger framed the raise around scale: “Enterprise AI is skyrocketing,” he said, with organizations “promoting AI agents at velocity and adoption rates never seen before.”
Zenity’s platform is built around three functions it calls Surface, Enforce and Protect: discovering agents and their posture, enforcing policy, and protecting against runtime misuse. The company argues security has to evaluate an agent at the decision point, weighing context and intent immediately before an action executes, across ecosystems including Microsoft, OpenAI, Claude, Google’s Gemini and custom agent frameworks. Zenity describes its work as AI-agent security, governance and runtime enforcement, a narrower and more accurate label than “autonomous defense,” which neither its product pages nor its funding coverage use. Zenity is not a replacement for identity and access management, endpoint detection or data-loss prevention. It adds a layer specific to what an agent is trying to do and whether it should be allowed to do it.
Adoption is nearly universal, but the data behind it is not ready
Dun & Bradstreet’s 2026 AI Momentum Survey of 10,000 businesses found that 97% report active AI initiatives and 56% plan to increase AI investment over the next 12 months. Only 5% say their data is adequately ready to support the work, and 60% report at least some measurable return, including 24% describing broad or strong returns. Read together, the numbers describe a market where almost everyone has deployed something and almost no one has finished the groundwork underneath it.
The gap above is where the Anaconda and Zenity announcements land. Agents earn their value by reaching enterprise data and systems. The same connection that gives an agent business context is the connection that creates exposure, and weak data readiness compounds the problem: an agent operating against poorly governed data is harder to audit and harder to trust with write access.
What buyers should ask before they sign
Security and platform teams evaluating the AI-agent security category have specific, answerable questions to put to any vendor. Can the platform discover every agent in use, including ones built outside official channels? Does it map each agent’s identity, credentials, data access and tool permissions? Can it inspect and block a tool call before it executes, rather than only logging it after the fact? Does it work across models from more than one provider, or does it lock a buyer into a single vendor’s agent ecosystem? And when a vendor cites vulnerability or exploitation statistics, as Enkrypt did with its MCP scan, has anyone outside the company validated the methodology?
Procurement for the category now belongs to more than one desk. CISOs, CIOs, data and AI leaders, and platform engineering teams each have a stake in agent inventory, tool-call inspection, data lineage and audit evidence, and RFPs increasingly need to reflect the shared ownership rather than routing through a single security budget line.
The perimeter has moved to actions, not prompts
Anaconda’s acquisition and Zenity’s funding round are not evidence that enterprises have solved AI-agent risk. They are evidence that buyers, and the investors betting on them, have accepted agent security as a distinct budget line rather than a subset of generic AI governance. The category will keep consolidating as more platform vendors decide it is cheaper to acquire the capability than build it.
My take is that the vendors who matter won’t be defined by the size of their funding round. They will be defined by whether a control can stop an unsafe action before it runs, on infrastructure the buyer already trusts, without depending on a single model provider to stay honest.
The post Anaconda Buys Enkrypt AI as Zenity Raises $125 Million: AI Agent Security Becomes Enterprise Infrastructure appeared first on .
