Adoption outran the controls
97 million SDK downloads a month, 41% of technical leaders in production, and a majority of public servers carrying exploitable risk. MCP is having the year every successful protocol has.
MCP adoption is at infrastructure scale and its security posture is not. Only a small fraction of public servers default to OAuth.
This is the normal shape
Every protocol that solves a real integration problem gets adopted before it gets an authorisation model. HTTP, SMTP, npm, container registries — all the same curve. The gap between "this makes integration trivial" and "this needs governance" is where incidents live.
What is unusual is the compression. Roughly 97 million downloads a month and 41% production penetration inside two years is faster than any of those precedents, which means less time for the security practice to develop alongside.
Tool poisoning is the specific problem
An MCP server tells an agent what it can do, in text the agent trusts. Text an agent trusts is an injection surface. That is not an implementation bug in a particular server; it is a property of the pattern, which is why it needs a control at the gateway rather than a patch.
Failures trace back to scaling MCP access before the governance layer could hold it.
The order that works
Practitioners report the same sequence: gateway, identity layer, audit trail as architecture from day one, then scale. That is precisely what the new registry and agent-identity products are sold to retrofit — and retrofitting is more expensive than building it in, as it always is.
Meanwhile the surface keeps growing. Latency is now a per-call parameter, models are a runtime choice, tools are discovered dynamically. Every one of those is a capability, and every one is another thing that has to be scoped.
The controls are arriving. They are arriving second, which is the part worth planning around.
ITECS — MCP Tool Poisoning: Enterprise AI Agent Security in 2026 → · LangProtect — MCP Security: Enterprise Guide to Securing AI Agents → · Snowflake — Enterprise AI Security: Agentic Controls and MCP Governance →