There is a number out this month that ought to stop people cold, and it will not, because it arrived dressed as a security report instead of a headline.

Nine out of ten of the little servers that let AI reach into your accounts have no lock on the door.

When you connect an AI assistant to your email, or your calendar, or your files, you are not handing it a password each time it looks. You connect it once. After that it holds a key. The key sits in the middle, between the AI and your account, in a piece of software most people have never heard of and will never see.

That piece of software has a name. It is called an MCP server. There are thousands of them now. Some are built by big companies. Most are built by somebody over a weekend and put on the internet.

Here is what a group of researchers did. They went out and found six hundred and forty of these servers running live on the open internet. Then they ran real tests against four hundred and fourteen of them, not paper reviews, actual probes, across four separate sweeps in July. Of the four hundred fourteen they tested, three hundred eighty had no OAuth authentication at all. That is 91.8 percent. arXiv

OAuth is the lock. It is the thing that decides who gets in, how far they get, and for how long. Nine out of ten did not have one.

I did not take that number on faith, and neither should you. Three other groups counted the same thing a different way and landed in the same place. One audit of the official registry found 91.5 percent of three thousand and twelve servers running on static keys, personal tokens, or nothing at all, with only 8.5 percent using OAuth. Another group scanned about seven thousand servers and found 41 percent required no authentication whatsoever, with the same 8.5 percent on OAuth. A third research outfit reported the identical 8.5 percent figure. Guild + 2

Different people. Different piles of servers. Same answer.

Now here is the part that bothered me more than the lock.

Between two of those sweeps, three days apart, 193 servers that had been confirmed running were simply gone. That is 41.6 percent of them, vanished in seventy-two hours. The researchers read that as deployments being treated like disposable parts, with no security check imposed at the moment they go live. arXiv

Think about what that does to the idea of an audit.

You cannot inspect a thing that will not be there Thursday. You cannot hold anybody to a standard when the thing being measured evaporates before the measurement is finished. This is not a case of somebody failing the test. It is a case of the test never getting a chance to run.

What A Key Ought To Be

There is guidance out now from the people who work on machine identity for a living. Their advice is simple and it is correct.

A key handed to an AI should be cut for one job. It should stop working shortly after that job is done. And when one AI passes work to another, the second one should have to ask for its own key, not inherit the first one’s.

That is it. That is the whole recommendation.

The reason is easy to see. If a key is cut for one job and expires by supper, then somebody who steals it gets one job and one afternoon. If a key opens everything and never expires, somebody who steals it owns your account until you notice, and most people never notice.

We already know this in every other part of life. The fellow who comes to fix your furnace does not get a key to the house and the shop and the truck. He gets in, does the work, and goes. Nobody thinks that is unfriendly. It is just how a sane person hands out keys.

We have not done it here.

What I Am Looking At Right Now

I am not writing this from a distance.

The session that produced this post has three connections attached to it. Mail. Calendar. Files. I approved those myself, some time ago, and I have not looked at them since.

They were granted once. Nothing asks again. Nothing expires that I set. Whatever the AI does from here carries the same authority I handed over the day I clicked the button, and there is no gate anywhere in the middle that stops and asks whether this particular task needs this particular reach.

That is not an accusation. It is a description of the ordinary setup, on a major platform, working exactly as designed.

I want to be square with you about one more thing. The MCP protocol under all of this was built by Anthropic, and the AI that helped me draft this post is made by Anthropic. I am not going to write about a company’s plumbing using that company’s tool and leave that out of the telling. You should know where the hands came from.

The Half Nobody Owns

Back in July I split the agent protocol in my own framework into two halves, because it had become clear they were two different jobs.

One half is conduct. That is what the AI chooses to do — say when a gate is missing, say before an action runs instead of after, never describe an ungated action as governed.

The other half is provision. That is the lock itself. The scoped key. The expiry. The re-authorization at each handoff. None of that is something an AI can choose. Somebody has to build it.

The conduct half I can hold, and do. The provision half is not mine to build, and this month’s numbers say it is not getting built by much of anybody else either.

Nine out of ten doors, no lock. Four out of ten of the buildings gone in three days.

That is the state of it.

What You Can Actually Do Today

Go look at your own connections. Whatever assistant you use, there is a settings page listing what you have connected. Most people have never opened it.

Read what each one can reach. Ask yourself whether you meant to grant that much, for that long, forever.

Turn off the ones you do not use. That is not paranoia. That is the same instinct that makes you take the spare key back from the fellow who finished the job.

You cannot fix nine out of ten servers. You can fix yours.

This post was drafted with AI governed assistance and reviewed and directed by Michael S. Faust Sr. before publication.

Contact: micvicfaust@gmail.com

Post Library – Intelligent People Assume Nothing

How-To-Use-The-Working-Manner-Layer

TFB-Working-Manner-Layer (3)Download

© 2026 The Faust Baseline LLC | All Rights Reserved

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *