Why I Joined Enkrypt AI: Merritt Baer


Why I Joined Enkrypt AI
β
I choose to spend my life working in security because security defines the edges of how we interactβ with each other, with companies, with governments. I measure the ROI of basically everything, and I will spend a lot of time on my jobβ in my case, a really significant amount. And so, I ask myself, what will you do with your one wild and precious life?
β
The founders of Enkrypt AI met while doing Math PhDs at Yale. I donβt bring that up because Iβm dazzled by ivy, but because in AI securityβwhere the horizon keeps movingβyou want a team that doesnβt just chase relevance, they generate it. Research is where the rubber meets the road in AI, and we are among those who are actively reimagining the field of AI security.
β
This takes practical formsβ for example, our research has turned into redteaming, which turned into responsible disclosures, which turned into customers. In practice, that looked like us knocking on a companyβs door and saying: βHey, your model is vulnerable to surfacing CSAM. Hereβs our proof. Want help?β
β
Wendell Berry once wrote (about marriage, but still fitting): βYou do not know the road; you have committed your life to a way.β I believe that smart companies embody philosophical commitments.
β
Weβre also at an inflection point with data and interactions. For years, people called data βthe new oil.β Cute metaphor, but I always hated it. What matters is how data gets consumed, contextualized, and securedβespecially as AI systems are trained on it, act on it, and interact with us. The real security questions are no longer about locking down files in a folder; theyβre about safeguarding systems (hardware and software) interpreting and acting on data. I expect more and more data to be in aggregated, non-human-readable forms, because AIs are interacting with each otherβ and only convert back to natural language when they surface something to a human in the loop.
β
DLP isnβt the future, and no one will miss Microsoft Purview. Whatβs at stake isnβt just a miskeyed βname fieldββitβs the integrity of how humans and machines work together.
β
The research basis of the company matters to me in how we serve customers. Enkryptβs competitive advantage isnβt a static productβitβs the way we approach AI safety, security, and compliance. We redteam, we guardrail, we enforce policy. This means we can translate capabilities into broad offeringsβ We protect agentic capabilities (AI that actually takes actions) and LLM interactions (chatbots, Copilot, or your custom models), and we do MCP security. Importantly, we do it in an attestable wayβso when your βAI Governance Councilβ hands you that 40-page AI Governance doc, we can take that and enforce itβ and we can enforce if you want to have the EU AI Act provisions, or your companyβs 2026 policy, or the next AI regulation that will arise in California or Vietnam. There will always be a βnextβ in AI and we are already looking around the next corner.
β
Most CISOs I talk to already know their entities and employees are interacting with AI. Theyβve been told some version of, βgo do something about it.β Enkrypt helps us as CISOs move from aspiration to enforcement of safety and security commitments, which also means we can unlock new AI use cases safely. Thatβs the kind of ROI I want to spend my time on.
β
Frequently Asked Questions
AI red teaming is systematic testing of AI systems to find vulnerabilities before attackers do. It identifies risks like prompt injection, data exfiltration, and unsafe model outputs across 300+ risk categories.
- Proactively discovers model vulnerabilities before production deployment
- Translates research findings into responsible disclosures and fixes
- Enables companies to harden AI agents and LLMs against real-world attacks
Runtime guardrails enforce policy-based controls that block hallucinations, data leakage, and unauthorized tool use in real time. Enkrypt AI's agent guardrails operate at ultra-low latency without slowing agent execution.
- Intercept unsafe actions before they execute in production systems
- Enforce company-specific policies across all agent deployments
- Maintain performance while preventing data exfiltration and misuse
MCP scanning identifies vulnerabilities in server configurations and skill packages; MCP gateway adds a runtime enforcement layer that blocks malicious requests and enforces policies in real time. Together they provide end-to-end MCP governance.
- Scanning detects prompt injection, code injection, and context poisoning risks
- Gateway prevents exploitation by filtering and controlling access
- Combined approach covers discovery, curation, configuration, and enforcement
Enkrypt AI's policy engine translates governance frameworks into enforceable rules across agents, LLMs, and MCP infrastructure, reducing manual compliance effort by up to 90%. It supports NIST AI RMF, MITRE ATLAS, OWASP LLM Top 10, and emerging regulations.
- Centralized policy management enforces company and regulatory requirements
- Attestable enforcement demonstrates compliance to auditors and boards
- Adapts to new regulations (EU AI Act, California, Vietnam) as they emerge
If your AI systems are already acting on data without human oversight, Enkrypt AI's agentic guardrails and policy enforcement deserve a look. Book a demo to see how we enforce governance across your models, or start a free trial to test it yourself.


.jpg)

