There is a small comic risk in letting the chief executive near a new machine. David DeSanto acknowledged it himself when he titled a 2026 build diary, “Oh no… Our CEO is building again.” The machine was an NVIDIA DGX Spark, a compact AI computer with enough memory to run serious models locally. The software was Anaconda's new desktop experience. The CEO was at the keyboard, which is where he seems happiest.
He installed the application, downloaded a model, started an API server and created an agent called Test Subject. From download to conversation took less than three minutes, he reported, or roughly the span of making tea. The exercise had the trappings of a product demo, but its real subject was management. DeSanto believes leaders understand customers by using what the company ships. Slides can report friction. A keyboard makes you feel it.
That conviction suits an executive whose education came partly from breaking things. Before Anaconda, before six years at GitLab, DeSanto spent a long stretch in cybersecurity: validating products, studying vulnerabilities and malware, testing network defenses, and asking whether the confidence sold by a vendor could survive contact with an attack. His career has moved from code to security to product to the corner office. The old questions came along.
“Building things unlocked both the analytical and imaginative parts of my brain.”David DeSanto, writing for Anaconda
A career built around the failure case
DeSanto studied computer science at Millersville University of Pennsylvania, then earned a master's degree in cybersecurity from New York University. Early jobs included IT consulting and network administration. In 2006 he joined ICSA Labs, the independent security testing operation then associated with Verizon, and remained there until 2013. The work gave him a front-row seat to an awkward truth of technology: a product can behave impeccably in a brochure and quite differently under hostile conditions.
He moved to NSS Labs in 2013 and then to Spirent Communications in 2014, where he directed products and threat research. His public work from that period has a consistent temperament. In interviews he argued that security teams were too reactive. In an article on automated purple-team assessments, he urged organizations to test their defenses continuously with realistic attacks and turn the results into prioritized repairs. Hope, in this view, is a poor testing framework.
In 2015, DeSanto co-authored Threat Forecasting: Leveraging Big Data for Predictive Analysis. The book warned against treating historical incidents as a sufficient map of future breaches. Its practical interest was foresight: combining data, scenarios and threat intelligence to see trouble before it acquired a help-desk ticket. He also spoke at international conferences about cloud security, SSL and TLS, and the security of satellite-navigation systems. His territory was broad; the method was stable. Gather evidence. Model what could go wrong. Test the model.
GitLab: one product, many constituencies
In 2019, DeSanto joined GitLab to help expand its highest enterprise tier by building security into the development lifecycle. It was a neat turn: the researcher who had tested security products now worked inside the system where software was planned, written, scanned and released. He rose through product leadership, became vice president of product, and in 2022 took the chief product officer role.
His remit included product management, monetization, operations and user experience. GitLab's single-platform pitch forced a product leader to balance developers, security professionals, operators, executives and regulated customers. Under his leadership, the company launched GitLab Duo, its AI features; GitLab Dedicated, a single-tenant service for customers with stricter requirements; and broader security and compliance capabilities inside the platform.
GitLab also taught DeSanto the habit that later put him in front of the DGX Spark. The company used GitLab to ship GitLab. “Dogfooding” is an inelegant word for an elegant discipline: when employees live inside their own product, little indignities become difficult to ignore. DeSanto brought the practice to Anaconda because its audience spans veteran data scientists and people taking a first step into AI. A tool can be technically powerful and still leave a new user staring at the door.
His security interests did not recede as his title grew. In 2024 he served as a general member representative on the Open Source Security Foundation's governing board. Open source software carries a peculiar social contract: enormous collective usefulness coupled with responsibility spread across maintainers, companies and users. Learning to govern that commons without smothering it would soon become his full-time problem.
The four-part answer
Anaconda appointed DeSanto chief executive and a director on October 16, 2025. He has said four things drew him: the technology, the open-source community, the people, and the opportunity to shape enterprise AI. As a developer, he already knew the distribution. As a security executive, he understood the difficulty hiding beneath its convenience. Python packages make experimentation wonderfully easy. Enterprises require provenance, repeatability, policy and a record of what entered production.
The tension can be stated without drama. Builders want choice. Companies want control. Closed systems simplify some decisions while concentrating data and dependency with a vendor. Open systems create portability and inspection while leaving more integration and governance to the adopter. DeSanto's Anaconda wants to make those desires coexist in the same platform.
His local build was a miniature of that thesis. The model ran on hardware at his desk. No cloud service needed the data. The interface hid much of the dependency work. The setup remained real enough to expose gaps. In the second stage, he connected the Spark as an inference engine to a Mac Studio and built collaborating product-management and coding agents. For industries with air-gapped environments, local control is an operating requirement rather than a lifestyle preference.
“People deserve the option to choose, inspect, and own the AI they build.”David DeSanto on open-weight AI
Three deals draw one diagram
During 2026, Anaconda made three acquisitions that reveal DeSanto's platform plan more clearly than a slogan could. Outerbounds, announced in the spring, brought production orchestration built around Metaflow: workflows, compute, artifacts and deployment. Kilo Code followed in July, bringing an open, model-agnostic coding agent used by more than three million developers. In August came Enkrypt AI, which tests and governs models, agents and the MCP servers that connect them to tools.
The sequence extends from the first prompt to the production workload. It also returns to DeSanto's old terrain. An AI agent can choose tools, call services and act with a degree of autonomy. Every connection is another surface to test. Enkrypt reported finding vulnerabilities in 73 percent of 25,000 MCP servers it scanned over two months. The figure gives contemporary scale to a familiar security lesson: unexamined convenience accumulates risk.
DeSanto speaks about a “trillion-token enterprise,” a phrase that makes AI consumption sound like a utility meter spinning in a storm. His practical concerns are recognizable: cost, data sovereignty, security and vendor dependence. Kilo can route work among hundreds of models. Open-weight models allow companies to inspect and run systems inside their own environments. Policy must travel with the workload, because the workload will not politely remain in one product box.
Keeping a hand on the machine
The danger for a chief executive with a builder's identity is romanticizing the keyboard. A company of Anaconda's reach cannot be run as one enormous personal project. DeSanto's own description of the CEO job is wider: strategy, culture, operations and results, with responsibility for growing carefully, supporting people and delivering customer value. His hands-on sessions matter because they supply texture to those obligations, not because they replace them.
Still, there is something cheering about a CEO who names an agent Test Subject and admits his Python bias. Enterprise technology often arrives dressed for a tribunal. DeSanto brings the habits of the lab: make a hypothesis, assemble the equipment, keep notes, invite failure to be informative. The personality visible in his writing is earnest, technically curious and lightly mischievous. He ended one build installment by borrowing Samuel L. Jackson's warning from Jurassic Park. Even governance may benefit from timing.
His next test is considerably larger than a desktop computer. Anaconda serves a vast open-source community while selling the controls large organizations demand. It must integrate acquisitions without sanding away the qualities that made them useful. It must make AI safer without making builders miserable. And it must prepare for a future DeSanto has publicly predicted, one in which Python may eventually lose its place as AI's leading language.
A threat forecaster would avoid certainty. A product leader would draw a roadmap. A builder would open the box. DeSanto has been all three, and Anaconda's wager is that the combination can turn open AI into dependable infrastructure. The proof will arrive the way it always has in his career: when the system meets pressure and keeps working.