Enterprise adoption of Model Context Protocol (MCP) is creating a new infrastructure security gap as AI agents connect to servers outside conventional cloud governance. A study covering 15,465 published MCP servers found weak controls around hosting location, domain ownership, and persistent permissions, raising concerns about data residency and supply chain oversight for organizations.
What the research uncovered
The research, commissioned by OX Security, analyzed publicly accessible MCP servers used by AI agents to connect with external systems. Nearly all servers examined lacked enforceable policies on where they could be hosted, allowing deployment on foreign networks, consumer-grade connections, or even abandoned domains. Persistent permissions granted to AI agents further complicated oversight, as access rights remained active even after initial use.
Anthropic introduced MCP in late 2024 as a standardized method for AI agents to interact with external data sources and tools. While the protocol has gained traction in developer tooling and enterprise automation, its rapid adoption has outpaced governance frameworks, leaving organizations exposed to unintended infrastructure risks.
Why governance gaps matter
The findings highlight operational challenges for enterprises scaling AI deployments. Without controls on hosting locations, organizations risk violating data residency requirements or exposing sensitive workflows to untrusted networks. Abandoned domains hosting MCP servers could also become vectors for supply chain attacks, as expired ownership might allow malicious actors to hijack connections.
Persistent permissions add another layer of complexity. AI agents retaining access to external systems indefinitely create audit and compliance challenges, particularly in regulated industries where access logs and revocation processes are mandatory. The lack of standardized governance tools for MCP means organizations must manually track and manage these connections, increasing operational overhead.
What operators can do
Enterprises using MCP should inventory all published servers and enforce hosting policies that align with data residency and security requirements. Automated discovery tools, like those offered by OX Security, can help identify rogue or misconfigured servers. Organizations should also implement time-bound permissions for AI agents, ensuring access is revoked after use unless explicitly renewed.
For professionals: Audit MCP server deployments for hosting location and domain ownership. Implement automated tools to monitor persistent permissions and enforce time-bound access for AI agents. Review data residency policies to ensure compliance with regional regulations.
Companies mentioned
Automated pipeline · Security
Synthesized from 1 industry feed on 25 Sep 2026. Passed independent editor verification (score 85/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — New story No recent or in-pipeline article covers MCP server security risks in enterprise AI infrastructure.
- Checking for duplicates — New story pre_write:; No recent or in-pipeline article covers MCP Servers and Model Context Protocol infrastructure risks.
- Writing the article — Draft created article_id=604 slug=mcp-servers-reveal-enterprise-ai-infrastructure-risks
-
Editor review — Approved
- Score: 85/100
- Factual grounding: The draft states 'Anthropic introduced MCP in late 2024' but the source only says 'Created by Anthropic in late 2024' without specifying the introduction date. While the year is correct, the term 'introduced' is not directly supported by the source phrasing.
- Style compliance: The standfirst exceeds the recommended length (current: 68 characters
- recommended: <60 for clarity).
- Quote integrity: The 'For professionals' callout is not a verbatim quote and does not require blockquote formatting, but it is correctly presented as a callout and not misrepresented as a quote.
- No copied phrasing: The phrase 'weak controls around hosting location, domain ownership, and persistent permissions' closely mirrors the source phrasing 'weak controls around hosting location, domain ownership and persistent permissions'. While the idea is paraphrased, the structure and key terms are nearly identical.
- Generating reader Q&A — Generated 4 items
- Assigning hero image — Reused library image reused image #19
- Linking related stories — Linked 5 relations from 339 candidates
- Publishing — Published mcp-servers-reveal-enterprise-ai-infrastructure-risks
- Mastodon — Posted https://mstdn.social/@hostingpaper/117332481248377126




Discussion · coming soon
Be the first to join the thread when community discussion launches.