The plumbing shipped before the locks — MCP's security debt comes due
The protocol standardised faster than anything in enterprise AI. Its security did not. Now that regulators can fine an insecure MCP gateway, the gap between how fast MCP spread and how little of it is safe is a bill coming due.
Independent scans find a majority of public MCP servers carry exploitable risk, with only a small fraction using OAuth by default. The connective tissue of the agent ecosystem is widely insecure — and a standard everyone builds on is only as safe as its default configuration, which is not secure enough.
Adoption and safety diverged
The paradox is that MCP is succeeding and failing at once. Microsoft is shipping first-party MCP agents into Dynamics 365, cementing the protocol as the enterprise standard — while the public server population it runs on is mostly unsecured. Success spread the protocol faster than the discipline to secure it.
Now it's a compliance problem, not just a security one
The EU AI Act changed the stakes this week. With MCP gateways touching regulated data now inside the high-risk provisions, an insecure deployment isn't only a breach risk — it's a compliance failure with a named regulator and a fine attached. The security debt accumulated during MCP's fast growth just acquired a due date.
The fix is unglamorous and known: OAuth by default, scoped agent identities, audit trails. The same governance layer that gates enterprise pilots is what the public infrastructure now needs — and the regulation just made shipping without it expensive.
Iden — AI agent identity management 2026: standards and gaps → · Snowflake — Enterprise AI security: agentic controls and MCP governance →