// news · agents2026-08-03source: idenhq / snowflake

Independent scans find most public MCP servers carry exploitable risk — and few use OAuth

Security has not kept pace with MCP adoption. Independent scans find a majority of public MCP servers carry exploitable risk, with only a small fraction using OAuth by default — and now that MCP gateways touching regulated data fall under the EU AI Act's high-risk provisions, the gap is a compliance problem, not just a security one.

The finding is the shadow side of MCP's success. The protocol standardised fast and adoption soared, but a majority of public servers carrying exploitable risk means the connective tissue of the agent ecosystem is widely insecure. A standard everyone builds on is only as safe as its default configuration, and the default is not secure enough.

OAuth's absence is the specific gap. With only a small fraction of public MCP servers using OAuth by default, most expose tools and data without the authorization layer that would scope what an agent can reach — precisely the identity-and-access problem that stalls most enterprise agent pilots, now visible in the public infrastructure.

The EU AI Act raises the stakes. With MCP gateways on regulated data now in scope of the high-risk provisions that became enforceable this week, an insecure MCP deployment is not just a breach risk but a compliance failure with a named regulator. The security debt the ecosystem accumulated during its fast growth is now coming due.

See our analysis →

Iden — AI agent identity management 2026: standards and gaps → · Snowflake — Enterprise AI security: agentic controls and MCP governance →