BlueRock Security went looking for Model Context Protocol servers on the public internet. MCP is the plumbing that lets an AI agent call your tools, read your files, hit your internal APIs. They analyzed more than 7,000 of these servers and found 492 sitting on the open internet with no authentication at all. No password. Separately, they found a server-side request forgery bug in Microsoft’s MarkItDown MCP server. Feed one of those a URL and it fetches the page from inside the network. By their count, 36.7% of the servers they looked at carry the same latent exposure. On AWS that path reaches the instance metadata service, which is where cloud credentials live.
Run the multiplication: 36.7% of 7,000 is roughly 2,570 servers. The 492 unauthenticated ones are about 7% of the sample. Their write-up of the MarkItDown vulnerability has the technical detail.
Here’s what I can’t get past. No procurement process on earth produces 492 unauthenticated internet-facing servers. That number is what happens when people who are good at their jobs wire up something useful on a Thursday afternoon and never tell anyone.
Which brings me to the two numbers that actually run this post. On April 3, 2026, Federal Reserve economists published a research note monitoring AI adoption in the U.S. economy. Using the Real-Time Population Survey, it puts 41% of the US workforce using generative AI for work as of the November 2025 collection. In the same note, drawing on business surveys, only 18% of firms had formally adopted AI by year-end 2025.
Why you can’t just subtract those
You can’t. Different units, different instruments, and anyone who writes “the 23-point shadow AI gap” is selling you something. Workers are the unit in the 41%. Firms are the unit in the 18%, and firm counts are dominated by small businesses, of which there are millions. Weight the same note’s data by employment instead and 78% of the labour force works at a firm using AI. Sector spread is wide: professional services around 33%, finance around 30%.
So three defensible numbers coexist at once. Most workers work somewhere that uses AI. Most firms have never formally adopted it. And two in five workers use it on their own. Nobody has measured the overlap between the third statement and the first two, and that overlap is what decides whether your security model is fiction.
Now put the governance data beside it. Deloitte surveyed 3,235 senior leaders across 24 countries in August and September 2025 for its State of AI in the Enterprise work, published in 2026. Roughly one in five report a mature governance model for autonomous systems. Meanwhile 74% expect to deploy agentic AI within two years, and 79% report challenges with adoption. Skills, not technology, is the barrier leaders name most.
Bon. So the governance being drafted right now is being drafted for the sanctioned deployment. Policy covers the pilot that has a budget line, a named owner, and a slide in the steering committee deck.
And every headline percentage we argue about has the same blind spot. Enterprise surveys report 86% of firms with AI in production and 97% of executives saying they deployed agents in the past year, against 34% who say they trust what those agents do. That 52-point spread gets framed as a scaling bottleneck. Maybe. I’d note the Lumenova roundup carrying those figures doesn’t publish the instrument or the sample, so treat them as directional at best. But even taken at face value, all four percentages describe things somebody chose to tell a surveyor about.
I keep coming back to MIT NANDA’s The GenAI Divide, from July–August 2025. About 95% of generative AI pilots showed no measurable P&L impact. Behind that number: 300-plus enterprise deployments, 52 executive interviews, 153 leader surveys, no vendor funding. Except 95% is a statement about pilots. A pilot is a funded project. Unsanctioned use isn’t in the numerator or the denominator, which means the most-used AI at a lot of companies is absent from the most-cited study about whether AI works at companies.
The attacker side has stopped waiting for the paperwork. CrowdStrike’s 2026 Threat Hunting Report came out August 3. Their report tracks 290-plus named adversaries and puts AI-enabled attacks up 89% year over year. In 88% of documented cases from January to June 2026, the gap between disclosure and exploitation of AI infrastructure ran under 48 hours. CrowdStrike sells the remedy, so discount accordingly. Discount it and the structural point survives anyway: a 48-hour patch window assumes you know the thing exists. Those 492 servers are not in anyone’s asset inventory. You cannot patch in two days what you’ll discover in eight months.
The part that argues against me
Now the counter I can’t dismiss: much of this gap may be definitional. A lot of that 41% is somebody asking a chatbot to make an email less rude, which requires no governance beyond not pasting the customer list into it. Formal adoption questions also undercount badly in the other direction. A firm running Copilot inside its Microsoft licence may not describe itself as having adopted AI, so some of the missing 82% is governed usage that failed a survey wording test. Productivity evidence is consistent with the consequential volume being small, too. My number from the Penn Wharton Budget Model line of work is roughly 1.1% aggregate productivity. A projection, not a measurement, and I’m reading it second-hand rather than from the model output.
What would change my mind is a firm-level survey that asks for a tool inventory instead of an adoption status. Count the API keys, count the MCP endpoints, count the browser extensions with document access. Nobody publishes that, which is suspicious, quand même.
There’s also a version of this where the shadow adoption is the good news. Bottom-up tool use by people who understand their own work is how spreadsheets got into finance, and nobody wrote a governance framework for VisiCalc first.
The action here isn’t a policy document. It’s a count, and it’s boring, and you can start it this week: ask what credentials the tools your agents call actually hold, then check that answer against the network instead of against the README. Me, I’d start with anything that can fetch a URL on your behalf. Two of those 492 servers belong to someone reading this, and it isn’t the security team that stood them up.