K
Kilo
Guest
Agents write most new code at the companies we talk to, and the tools that made that possible are excellent at it. Robert Björne, Product Owner at IntraPhone, told us his team "went from being blocked by two decades of backlog to running out of tickets" with Kilo, and in our survey of AI-native builders, 63% said they are moving toward agent swarms in some form. Writing code stopped being the constraint a while ago.
What those tools did was narrow the job to code and tie it to one lab's models. The actual work of an AI-native builder is wider than that. It includes the notebook where the analysis lives, the conda environment the notebook and the service both depend on, the open-weight model that would do the routine work at a tenth of the cost, the local model required for data that cannot leave the building, and the security policy that decides what any agent is allowed to touch.
Today we are releasing Kilo Desktop, the newest surface in AI Workspaces, to bring all of it into one app. It is also the entry point to the rest of Anaconda's stack, which carries the work from idea to deployment.
Across Anaconda's acquisitions of Kilo Code, Enkrypt AI, and Outerbounds, we kept hearing the same four requirements from teams whose agents had outgrown their tools. Each shaped Kilo Desktop.
Frontier labs such as OpenAI, Anthropic, and Google build remarkable models, and teams want them for their hardest problems. Each lab's agent harness, however, runs only that lab's models, which turns a technical decision into a procurement decision. If an open-weight model from NVIDIA, Moonshot, MiniMax, or Z AI would do a routine refactor at a fraction of the cost, you should be able to use it without installing a second tool and asking security to review it.
Kilo Desktop gives you native access to more than 500 models through one interface, and you can switch per task. When you would rather not choose, Auto Efficient checks each request against Kilo Bench, our own coding benchmark, and routes it to the cheapest model that has proven capable of that kind of work.
Models you host or subscribe to elsewhere plug in through a custom endpoint with your own key. For work that must never leave the machine, a built-in local model server runs open models directly on your hardware, with one setting that decides whether those requests carry the full agent toolkit or run light without it.
Sign in with ChatGPT, another new feature of Kilo, opens every Kilo surface to users who have existing OpenAI plans without extra logins or token costs.
An agent that writes whole services performs better when it has a plan. Kilo Desktop's Plan agent reads your project and returns a step-by-step implementation plan without touching a line, and only after you approve it does the Code agent split the plan into subtasks and run them in parallel with sub-agents. The Ask agent answers questions without changing anything, Debug finds what broke and fixes it, and custom agents cover whatever those four do not.
Parallel sub-agents on the desktop are a smaller instance of the Agent Swarms we are also bringing to VS Code today through Kilo, where several agents build in parallel, share context, and keep token costs down. Björne describes the shift as "turning what one developer does in a day into what a small team does."
Until now, agentic coding tools have largely left the notebook alone, and getting help with one still means pasting cells into a chat and pasting answers back. In Kilo Desktop, the agent edits the notebook directly while you watch its cursor move through the cell with the data loaded. The environment the notebook runs in is part of the app too; Kilo Desktop creates and manages conda environments and draws from our catalog of more than 19,000 vetted packages, so the agent has its dependencies before the first prompt and each of them has passed our review.
Workspaces follow from the same conclusion. Real work rarely lives in one folder, so a Kilo Desktop workspace is a named group of folders from your machine, which lets the agent read an analysis in one repository while it writes the service that depends on it in another. Chats, notebooks, diffs, and terminals open as tabs you arrange however the review demands, and any of them pops out onto a second monitor and snaps back when you finish.
An agent that can call any tool and read any dataset is a security surface, and the numbers say so. Our Enkrypt AI team scanned 268,210 agent tools across 25,264 MCP servers over four months and found vulnerabilities in 73% of them. A policy document cannot keep up with that; the environment has to enforce the policy itself. In Kilo Desktop, your administrators decide which models and providers people can use and from which geographies, what each agent may do, and which skills and MCP servers it can install, with the new Anaconda MCP extending the same vetting to agent tool calls. The developer sees the full landscape and works inside the boundaries you drew.
Kilo Desktop is where work starts, and we built the rest of the Anaconda Platform so that what starts there arrives in production unchanged. The same vetted packages, 13,000 of them newly added this release, and the same curated models flow from the desktop into Metaflow workflows, and FastBakery turns the resulting dependency set, native libraries included, into reproducible container images that pip-only tooling cannot produce. Before anything ships, our autonomous red-teaming attacks models, agents, and MCPs across more than 300 attack categories and adapts as the target hardens, and guardrails approve, modify, or block risky behavior at runtime.
We also published the Agent Incident Registry, a verified, source-backed record of publicly reported agent incidents. We think buyers should be able to check security claims against evidence, including our claims, and until now there was nowhere to do that.
Agentic coding was the first step. The AI-native development environment is the whole job in one place: a person directing agents that write, analyze, and test, with any model a dropdown away, notebooks and environments as native as source files, and the security team's policy running inside the tool. We built Kilo Desktop to be that place, and we built the platform behind it so the work survives the trip to production.
Kilo Desktop is available to download today. The rest of the release is on our launch page, and we will show all of it live at Anaconda Scale on October 15; registration is open.
Download Kilo Desktop
What those tools did was narrow the job to code and tie it to one lab's models. The actual work of an AI-native builder is wider than that. It includes the notebook where the analysis lives, the conda environment the notebook and the service both depend on, the open-weight model that would do the routine work at a tenth of the cost, the local model required for data that cannot leave the building, and the security policy that decides what any agent is allowed to touch.
Each of those lives in a separate tool today, with its own login, its own permissions, and its own gap for context to fall through.
Today we are releasing Kilo Desktop, the newest surface in AI Workspaces, to bring all of it into one app. It is also the entry point to the rest of Anaconda's stack, which carries the work from idea to deployment.
What Kilo Desktop Does Differently
Across Anaconda's acquisitions of Kilo Code, Enkrypt AI, and Outerbounds, we kept hearing the same four requirements from teams whose agents had outgrown their tools. Each shaped Kilo Desktop.
The model is a choice, not a vendor
Frontier labs such as OpenAI, Anthropic, and Google build remarkable models, and teams want them for their hardest problems. Each lab's agent harness, however, runs only that lab's models, which turns a technical decision into a procurement decision. If an open-weight model from NVIDIA, Moonshot, MiniMax, or Z AI would do a routine refactor at a fraction of the cost, you should be able to use it without installing a second tool and asking security to review it.
Kilo Desktop gives you native access to more than 500 models through one interface, and you can switch per task. When you would rather not choose, Auto Efficient checks each request against Kilo Bench, our own coding benchmark, and routes it to the cheapest model that has proven capable of that kind of work.
Models you host or subscribe to elsewhere plug in through a custom endpoint with your own key. For work that must never leave the machine, a built-in local model server runs open models directly on your hardware, with one setting that decides whether those requests carry the full agent toolkit or run light without it.
Sign in with ChatGPT, another new feature of Kilo, opens every Kilo surface to users who have existing OpenAI plans without extra logins or token costs.
Directing an agent means planning before building
An agent that writes whole services performs better when it has a plan. Kilo Desktop's Plan agent reads your project and returns a step-by-step implementation plan without touching a line, and only after you approve it does the Code agent split the plan into subtasks and run them in parallel with sub-agents. The Ask agent answers questions without changing anything, Debug finds what broke and fixes it, and custom agents cover whatever those four do not.
Parallel sub-agents on the desktop are a smaller instance of the Agent Swarms we are also bringing to VS Code today through Kilo, where several agents build in parallel, share context, and keep token costs down. Björne describes the shift as "turning what one developer does in a day into what a small team does."
Data science is development
Until now, agentic coding tools have largely left the notebook alone, and getting help with one still means pasting cells into a chat and pasting answers back. In Kilo Desktop, the agent edits the notebook directly while you watch its cursor move through the cell with the data loaded. The environment the notebook runs in is part of the app too; Kilo Desktop creates and manages conda environments and draws from our catalog of more than 19,000 vetted packages, so the agent has its dependencies before the first prompt and each of them has passed our review.
Workspaces follow from the same conclusion. Real work rarely lives in one folder, so a Kilo Desktop workspace is a named group of folders from your machine, which lets the agent read an analysis in one repository while it writes the service that depends on it in another. Chats, notebooks, diffs, and terminals open as tabs you arrange however the review demands, and any of them pops out onto a second monitor and snaps back when you finish.
Governance belongs in the tool
An agent that can call any tool and read any dataset is a security surface, and the numbers say so. Our Enkrypt AI team scanned 268,210 agent tools across 25,264 MCP servers over four months and found vulnerabilities in 73% of them. A policy document cannot keep up with that; the environment has to enforce the policy itself. In Kilo Desktop, your administrators decide which models and providers people can use and from which geographies, what each agent may do, and which skills and MCP servers it can install, with the new Anaconda MCP extending the same vetting to agent tool calls. The developer sees the full landscape and works inside the boundaries you drew.
Beyond the Laptop
Kilo Desktop is where work starts, and we built the rest of the Anaconda Platform so that what starts there arrives in production unchanged. The same vetted packages, 13,000 of them newly added this release, and the same curated models flow from the desktop into Metaflow workflows, and FastBakery turns the resulting dependency set, native libraries included, into reproducible container images that pip-only tooling cannot produce. Before anything ships, our autonomous red-teaming attacks models, agents, and MCPs across more than 300 attack categories and adapts as the target hardens, and guardrails approve, modify, or block risky behavior at runtime.
We also published the Agent Incident Registry, a verified, source-backed record of publicly reported agent incidents. We think buyers should be able to check security claims against evidence, including our claims, and until now there was nowhere to do that.
The Paradigm, Stated Plainly
Agentic coding was the first step. The AI-native development environment is the whole job in one place: a person directing agents that write, analyze, and test, with any model a dropdown away, notebooks and environments as native as source files, and the security team's policy running inside the tool. We built Kilo Desktop to be that place, and we built the platform behind it so the work survives the trip to production.
Kilo Desktop is available to download today. The rest of the release is on our launch page, and we will show all of it live at Anaconda Scale on October 15; registration is open.
Download Kilo Desktop