On Wednesday night, the legal sparring between AI gateway startup Runlayer and HR tech giant Rippling came to an abrupt halt, with both companies dropping their respective lawsuits against each other. In a highly unusual outcome for such high-stakes corporate litigation, no settlement was reached, and no money exchanged hands, not even for lawyers’ fees, according to court documents reviewed by TechCrunch. The immediate aftermath saw Rippling swiftly launch its much-anticipated MCP (Machine-to-Cloud Protocol) gateway, the very product that lay at the heart of the dispute and directly competes with Runlayer’s core offering, underscoring the raw competitive drive within the burgeoning AI enterprise sector.
The Genesis of a Conflict: A Cautionary Tale for the AI Era
This public legal confrontation, though brief, serves as a stark cautionary tale for founders navigating the rapidly evolving landscape of artificial intelligence. In an era where the development of new software, particularly with advanced AI tools, has become remarkably efficient, the identity of one’s next competitor can be unpredictable. The Runlayer-Rippling saga exemplifies this, illustrating how a prospective customer can transform into a direct rival, a scenario increasingly plausible given the accelerated pace of innovation and product development in AI.
Runlayer, an early-stage startup that emerged from stealth in November 2025, quickly made waves in the AI security space. The company has successfully raised a substantial $42 million from prominent venture capital firms, including Khosla Ventures, with backing from notable investor Keith Rabois, and Felicis Ventures. At its helm is third-time founder Andrew Berman, a seasoned entrepreneur whose previous ventures include Nanit, a baby-monitor manufacturer, and Vowel, an AI video conferencing tool acquired by Zapier in 2024. Berman’s track record positioned Runlayer as a serious contender in its niche, attracting significant investor confidence.
The relationship between Runlayer and Rippling began as a seemingly promising collaboration. For over a year, Rippling engaged in extensive testing of Runlayer’s MCP gateway, with engineering teams from both companies working closely together. Such protracted testing phases are common in enterprise software adoption, allowing potential clients to rigorously evaluate a product’s capabilities, integration potential, and security features. However, according to Runlayer’s lawsuit, this lengthy evaluation never culminated in a customer agreement. Instead, Berman received a text message from a Rippling employee delivering an unexpected blow: Rippling was building its own MCP gateway and intended to release it as a product. The employee allegedly described Rippling’s nascent product as a "clone" of Runlayer’s offering, immediately raising alarms about intellectual property and fair competition.
The Technological Battleground: Understanding MCP Gateways
At the core of this legal and commercial clash is the MCP gateway, a critical piece of infrastructure in the emerging AI enterprise stack. An MCP gateway is designed to securely manage an enterprise’s AI agent requests for data residing in various other software systems. For example, when a human resources professional utilizes an AI agent to request details on the top five candidates for a specific job, including their contact information, that sensitive data must be retrieved from the company’s recruitment system. The MCP gateway acts as an intelligent intermediary, handling this retrieval process without granting the AI agent direct, unfettered access to the enterprise’s underlying software systems.
This secure intermediation is paramount for several reasons. Firstly, it prevents potential security vulnerabilities that could arise from AI agents having broad access to internal systems. Secondly, it allows for the implementation of granular access controls, such as employee role-based access, ensuring that managers have different data access privileges than interns, for instance. Thirdly, gateways facilitate observability, providing crucial logs, usage trails, and audit capabilities, which are essential for compliance, debugging, and understanding AI agent activity within the enterprise. Furthermore, these gateways can layer on additional features like data anonymization, compliance checks, and cost optimization for AI model usage, making them indispensable for safe and efficient AI deployment in large organizations. The technology is complex, critical, and represents a significant market opportunity, attracting both specialized startups and established tech giants.
A Chronology of Legal Maneuvers and Strategic Pivots
The legal "brouhaha" unfolded rapidly. Runlayer initiated its lawsuit, alleging that Rippling had violated contractual agreements established during the extensive product testing phase. The core of Runlayer’s claim centered on the idea that Rippling had leveraged confidential information and access gained during the evaluation period to develop a competing product.
Rippling, not one to back down, responded with a countersuit. Filed on August 10, 2026, Rippling’s legal action alleged that Runlayer was infringing upon some of its patents. This move was widely interpreted by Runlayer and industry observers as a strategic tactic to increase legal pressure, potentially inducing Runlayer to drop its initial suit by ratcheting up the financial burden of litigation and creating a diversion. Patent litigation can be notoriously expensive and time-consuming, often proving a significant deterrent for smaller, early-stage startups.
The legal battle escalated, with both parties entering the discovery phase. This period typically involves extensive information exchange, including documents, communications, and depositions, aimed at uncovering facts relevant to the claims. It was during these three weeks of intensive discovery that Runlayer ultimately decided to drop its lawsuit. Subsequently, Rippling also withdrew its countersuit. The outcome, with no financial settlement or even reimbursement for legal costs, is highly unusual in corporate litigation and suggests a mutual decision to cease hostilities without a clear victor in the legal arena. The public "flaming" between the companies, as evidenced by social media exchanges including those by Rippling CEO Parker Conrad, further highlighted the intensity of the rivalry.
Broader Implications: The Shifting Sands of AI Competition
While the lawsuits themselves concluded without a definitive legal ruling or financial outcome, the underlying tensions and the manner of their resolution offer profound takeaways for founders, investors, and established enterprises alike. The rapid pace of change in the AI landscape means that traditional models of technical evaluation and partnership, where enterprises engage in lengthy shoot-outs with startups, may need to be fundamentally rethought. Between the initial engagement and the culmination of a multi-month evaluation period, an enterprise’s internal capabilities, strategic priorities, and competitive landscape can shift dramatically. What begins as a potential partnership can, in a matter of weeks or months, morph into a direct competitive challenge.
Rippling’s actions, from testing Runlayer’s product to launching its own competing solution, underscore a broader trend among established tech companies: a strategic pivot into AI. Historically known for its robust payroll and benefits management platform, Rippling has demonstrated a remarkable agility in expanding its product portfolio. In the span of mere weeks, the company has not only entered the AI gateway market with its new MCP offering but also launched an employee ROI tool that can route to different AI models while dashboarding token spend by employee. This aggressive expansion positions Rippling in direct competition with major players in the AI infrastructure space, including Stripe, which recently acquired OpenRouter, Ramp with its own AI model router called "Router," and Databricks.
Furthermore, with its MCP gateway, Rippling has firmly planted its flag in the AI security business, tying AI access to employee roles—a critical feature for enterprise adoption. This move places Rippling in competition with not only Runlayer but also established security and infrastructure providers like Docker and Amazon Bedrock, which offer services related to secure AI deployment. Rippling’s strategy appears to be one of comprehensive integration, aiming to provide a full suite of AI management and security tools alongside its existing HR and IT management offerings, thereby creating a more cohesive and controlled environment for enterprise AI adoption.
For Runlayer, the legal battle, despite its unsettling conclusion, has not derailed its mission. The startup’s core pitch remains a broader bundle of AI agent security services tied to its gateway. This includes functionalities ranging from the secure creation and deployment of AI agents to the sophisticated detection of "shadow AI" agents—unauthorized or unmanaged AI instances running within an enterprise network, often unbeknownst to IT departments. This focus on comprehensive agent lifecycle management and advanced threat detection positions Runlayer as a specialist in a critical and rapidly growing segment of the cybersecurity market. The global AI in cybersecurity market size, valued at approximately $19.2 billion in 2023, is projected to reach over $100 billion by 2032, growing at a CAGR of more than 20%—underscoring the immense potential for specialized players like Runlayer.
Looking Ahead: The Future of AI Collaboration and Competition
The Runlayer-Rippling episode highlights a fundamental tension in the current tech environment: the balance between collaboration and competition, particularly in fast-moving fields like AI. Startups often rely on partnerships and early customer engagements with larger enterprises to validate their technology, gain market traction, and secure vital feedback. However, this case illustrates the inherent risks when a potential partner has the resources and strategic inclination to become a competitor.
For enterprises, the temptation to "build versus buy" is stronger than ever with the democratization of AI development tools and platforms. The ability to rapidly prototype and deploy AI solutions means that companies can quickly internalize capabilities that might otherwise be outsourced or licensed from startups. This trend necessitates a re-evaluation of how startups protect their intellectual property and how enterprises approach innovation—whether through acquisition, partnership, or internal development.
The legal landscape itself is struggling to keep pace with technological advancements. The "clone" accusation, while emotionally charged, often proves challenging to litigate successfully without clear evidence of patent infringement or breach of specific confidentiality agreements. The lack of a financial settlement in this case suggests either that the legal merits were ambiguous or that both parties recognized the immense cost and distraction of prolonged litigation, opting instead for a strategic retreat to focus on product development and market capture.
Ultimately, the Runlayer-Rippling saga will be remembered not for a landmark legal precedent, but as a vivid illustration of the cutthroat competition and accelerated pace of change defining the artificial intelligence industry. It underscores the imperative for startups to carefully manage their intellectual property and partnership agreements, and for enterprises to navigate the ethical and strategic complexities of evaluating and potentially competing with innovative smaller players. As AI continues its transformative march across industries, such competitive dynamics are likely to become more, not less, common, reshaping the very fabric of tech innovation.
