73% of MCP Servers Have Vulnerabilities.

A binding EU obligation took effect three days ago that catches almost every business running a chatbot. A scan of 25,000 MCP servers found vulnerabilities in nearly three quarters of them.

A binding EU obligation took effect three days ago that catches almost every business running a chatbot. A scan of 25,000 MCP servers found vulnerabilities in nearly three quarters of them. And a 27-billion-parameter model now runs on a gaming GPU. Not one of these is a model story.

The interesting layer has moved. Compliance attaches to how your system presents itself. Security holes live in the connective tissue between the model and your data. Cost collapses at the deployment layer. The model itself was the least eventful part of this week.

For two years the industry has organised its attention around model releases. Which one leads the benchmark, which one is cheapest, which one just got beaten. That habit is now actively misleading, because the three developments this week that will cost you real money or real legal exposure all sit one layer below the model.

Here is what happened, in order of how quickly it lands on you.

Article 50 Is Live — and Most Summaries Got It Backwards

On 2 August, the EU AI Act's transparency and information obligations under Article 50 became generally applicable and enforceable by national competent authorities across the EU.

Not phased. Not advisory. Enforceable, as of Sunday.

The confusion in circulation comes from the fact that 2 August 2026 was also supposed to be the date the Act's high-risk obligations took effect — and those did not arrive. The AI Omnibus, Regulation (EU) 2026/1744, came into force on 27 July and pushed them back.

The Distinction That Matters

  • Live and enforceable now: Article 50 transparency obligations. Chatbot disclosure, synthetic content marking, deepfake labelling.
  • Deferred to 2 December 2027: standalone high-risk systems under Annex III — including the employment, recruitment and worker-monitoring uses that most businesses were preparing for.
  • Deferred to 2 August 2028: AI embedded in products already regulated under Annex I, such as medical devices and machinery.
  • Also new: a prohibition on AI-generated non-consensual intimate imagery was added to Article 5, and the AI Office gained broader supervisory reach over vertically integrated AI providers.

So there are two ways to get this wrong, and I expect to see both. Some businesses will read "the AI Act got delayed" and conclude nothing applies — while running an undisclosed customer-service bot for EU users. Others will spend Q3 on high-risk conformity documentation for obligations that are sixteen months away.

The obligation that arrived is the cheap one to comply with and the easy one to overlook. The obligation everyone prepared for is the one that got pushed to December 2027.

Who Article 50 Actually Catches

This is the part worth reading twice, because the scope is broader than most people assume. Goodwin's summary is blunt: if your product talks to users, generates images, audio, video or text, or scores their emotions or biometrics, the duties apply — regardless of whether the system is classified as high-risk.

The four situations Article 50 covers, in plain terms:

  • AI systems designed to interact directly with people must make clear that the person is dealing with an AI, unless that is already obvious from context.
  • Providers of generative systems must mark synthetic output in a machine-readable format that can be detected as artificially generated.
  • Deployers of emotion-recognition or biometric-categorisation systems must inform the people exposed to them.
  • Deepfakes and certain AI-generated publications must be labelled as such.

Read that first bullet against your own stack. A support chatbot on your website serving EU customers. An AI-drafted email sequence. A voice agent handling inbound calls. An automated reply that a customer might reasonably take for a colleague.

If you run automations for clients, this is not only your compliance problem — it is a question your clients are about to ask you, and the agencies that have an answer ready will look considerably more competent than the ones improvising.

The One Exception

There is a narrow carve-out. Generative systems already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking requirement under Article 50(2). That is four months, and it applies to marking only — not to the disclosure obligations, which are live now.

The European Commission has published a Code of Practice on Transparency of AI-Generated Content developed through its AI Office, which is the natural starting point if you are working out what compliant marking looks like in practice.

One honest caveat: penalty exposure under the Act varies by which obligation is breached, and the headline figures circulating online mostly refer to the high-risk tier rather than to Article 50. I am not going to quote a number at you. If EU exposure is material to your business, this is a conversation with a lawyer rather than with a blog, and it is worth having in August rather than in December.

143,000 Vulnerabilities in the Connective Tissue

On 4 August, Anaconda announced its acquisition of Enkrypt AI, an AI security and compliance platform, folding pre-deployment red-teaming, runtime guardrails and regulatory compliance automation into the Anaconda Platform. It follows Anaconda's July acquisition of Kilo Code.

The acquisition itself is ordinary consolidation. The number Anaconda used to justify it is not.

The Scan

In the two months before the deal, Enkrypt scanned more than 268,000 tools — the individual functions AI agents call — across 25,000 MCP servers, and found more than 143,000 vulnerabilities affecting 73% of those servers.

Two caveats before anyone puts that on a slide. This is a vendor statistic published by the acquiring company on announcement day, which is the least neutral possible context. And 73% is the share of servers with any vulnerability, which is a much wider net than critical severity — Enkrypt's earlier public study of 1,000 servers put critical vulnerabilities at roughly a third, averaging around five findings each.

With both caveats applied, the direction is still ugly, and it matches everything else visible in this ecosystem. The Model Context Protocol went from a niche standard to near-universal plumbing in under two years, and security practice did not travel with it.

Why MCP Specifically

Because MCP is where your model touches your data.

A model on its own cannot do much harm. A model wired through an MCP server to your CRM, your document store, your email and your payment system can do a great deal, and every tool definition in that chain is a place where an instruction can be planted, a permission over-granted, or a description quietly changed.

This is the same structural point as the npm supply-chain attack on developer tooling last month: the model was never the target. The plumbing was.

Read This Against Last Week's Spec Release

The timing is worth noticing. The Agentic AI Foundation shipped the 2026-07-28 MCP specification eight days ago, and the largest changes in it were authorisation hardening — mandatory issuer validation, credentials bound to the issuer that minted them with no cross-server reuse, and the formal deprecation of Dynamic Client Registration.

Those changes exist because of exactly the exposure this scan measures. If you run MCP servers, the security case for migrating is now considerably stronger than the scalability case, and you have a twelve-month deprecation window rather than an emergency.

It also lands beside the 88.4% of organisations reporting agent-related security incidents earlier this year. That statistic never made sense to people who assumed the model was the risk. It makes complete sense once you look at the tool layer.

Qwen3.8 and the End of a Convenient Excuse

The third development is the one with the best long-run economics, and it quietly dismantles an objection I raised myself a week ago.

Max

Alibaba released Qwen3.8-Max, a 2.4-trillion-parameter flagship built for long-horizon coding, agentic workflows and professional collaboration. API access is available immediately, with open weights scheduled to follow. Reporting describes it as capable of sustained autonomous coding runs measured in days rather than hours.

Treat capability claims at launch as provisional — they come from the lab that built it — but the strategic point does not depend on the benchmarks. Alibaba is now shipping frontier-scale models with open weights following on a stated schedule, which is the same pattern Moonshot established with Kimi K3 and which 30 to 46% of US enterprise tokens routing to Chinese models already reflects.

The 27B That Runs on Your Desk

The more useful release is the smaller one. Alibaba also dropped Qwen3.8-27B as open weights, and Unsloth shipped day-zero support for running and fine-tuning it on 17GB of RAM or VRAM — a single RTX 4090, a Mac with 24GB of unified memory, or a combination of system RAM and VRAM.

When Kimi K3's weights landed last week I pointed out that Moonshot recommends supernode configurations of 64 or more accelerators, and that for most teams the sovereignty benefit of open weights was therefore theoretical. That objection does not apply here.

A 27-billion-parameter model with same-day fine-tuning support, running on hardware a developer already owns, is a genuinely different proposition. It puts the advisor model architecture — cheap controllable default, frontier escalation as the exception — within reach of a business with one workstation rather than a cluster.

It also means that the incident-response argument I made a week ago has a cheap answer now. If you want the ability to analyse your own logs without depending on a vendor's willingness to respond, that capability now costs one machine and an afternoon.

Two things to keep your feet on the ground. Licence terms on open-weight releases vary enormously and "open weights" is a marketing phrase rather than a legal status — check the actual file before you build a dependency. And Alibaba's position in this ecosystem is not uncomplicated, as the distillation dispute earlier this summer made clear.

The Layer Everyone Is Still Not Watching

Two smaller items from the same week complete the picture, and both point the same way.

Microsoft Research introduced Orchard, an open framework that separates agent training from execution, allowing developers to train agents in realistic environments before deployment. That is infrastructure for the discipline of testing an agent before it touches production — which, on the evidence of the last month, the industry needs.

And observability startup Groundcover raised on the premise that agent telemetry, memory and traces should never leave the enterprise's own cloud. The funding is unremarkable; the thesis is not. Ownership of evaluation and telemetry data is becoming a strategic position rather than an operational detail, because it is the only way to know what your agents actually did.

Training harnesses, telemetry ownership, tool-layer scanning, protocol authorisation, disclosure obligations. Every consequential development this week was about the scaffolding around the model. None of it was about the model.

This is the platform war resolving into something more mundane and more decisive than a benchmark race. The competitive question is shifting from which model you use to whether you can govern, observe, test and legally operate what you have built with it.

What To Do This Week

1. Answer the Article 50 Question Today

One question, answerable in ten minutes: does anything you run interact with EU users, or generate content shown to them?

If yes, walk the list. Does every AI-facing interaction disclose that it is AI? Is generated content marked? Are voice agents disclosing on connection? Have you told clients whose automations you built that this obligation now exists?

Most of this is a copy change and a settings toggle. The cost of doing it in August is a morning. The cost of doing it after a complaint is considerably higher.

2. Inventory Your MCP Servers and Their Tool Permissions

Not just which servers you run — which tools each one exposes and what each tool is permitted to touch. The scan measured tools, not servers, for a reason: 268,000 tools across 25,000 servers is roughly ten call-points per server, and each one is an authorisation decision somebody made quickly.

Then check whether any server you depend on is third-party and unreviewed. If you cannot name who maintains it, that is the one to look at first.

3. Scope Every Tool to Its Actual Job

The consistent finding across every incident this month is that the damage scaled with permission, not with capability. A tool granted read access does not become a breach. A tool granted write access to a system it never writes to is a standing invitation.

This is the same advice as last week and the week before, and it will be the same advice next week, because it remains the highest-return action available to a small team. Scope credentials. Cap blast radius. Prefer reversible actions.

4. Put One Open-Weight Model on One Machine

Now that 27 billion parameters fit on a single consumer GPU, the excuse is gone. Pick one workflow — classification, routing, summarisation, first-pass drafting — run it locally, and measure whether the output ships without correction.

That measurement is your Automation Ratio on the cheap tier, and it is the only number that tells you whether the four-category framework would let you drop a step from an expensive model to a cheap one, or from a model to a rule.

5. Decide Where Your Agent Telemetry Lives

If you cannot reconstruct what an agent did last Tuesday — which tools it called, with what arguments, against which records — you cannot investigate an incident and you cannot demonstrate compliance. Those are now two separate reasons to fix the same gap.

The Broader Read

There is a version of the last fortnight that reads as relentlessly negative. Models breaking out of test environments, three quarters of MCP servers carrying vulnerabilities, a new regulatory obligation landing on small businesses. I do not think that is the right conclusion, and I would not publish it.

What is actually happening is that the agentic layer is being industrialised. Standards are hardening, scanners are being built and acquired, disclosure obligations are being enforced, training harnesses are being open-sourced, and capability is arriving on hardware people already own. That is what a technology looks like when it stops being a demo.

The businesses that struggle through it will be the ones that bought a collection of tools and never owned a process — the exact failure mode I described in the tool delivery versus process ownership argument. When the obligation is to disclose, observe, scope and document, a tool collection has nothing to disclose from.

The ones that do well will not be the ones with the best model access. Nothing this week rewarded that. They will be the ones who can say what their systems do, prove it, and change it inside a week — which has always been a systems problem rather than a technology one.

None of the five actions above requires a new vendor, a new model or a budget approval. They require an afternoon and the willingness to look at what you already have. That has been the honest answer for a while, and this week did not change it.

Frequently Asked Questions

Does Article 50 apply to my business if I am not in the EU?

Potentially yes — the Act reaches systems placed on the EU market or whose output is used in the EU, not only EU-established companies. Location is not the test; who your system interacts with is closer to it. If you have EU customers or users, assume you are in scope until a lawyer tells you otherwise, and note that I am not one.

I heard the AI Act was delayed. Was it?

Partly, and the part that was delayed is not the part that just took effect. The AI Omnibus deferred high-risk obligations for standalone Annex III systems to December 2027 and embedded Annex I systems to August 2028. Article 50 transparency obligations were not deferred and became enforceable on 2 August 2026.

Does the chatbot disclosure have to be prominent?

The obligation is that the person is informed they are interacting with an AI system, unless that is obvious from the circumstances to a reasonably observant person. In practice, a clear statement at the start of the interaction is the straightforward route. The Commission's Code of Practice on transparency is the reference to work from rather than anyone's blog summary, including this one.

Is the 73% MCP vulnerability figure trustworthy?

Treat it as directional rather than precise. It comes from a vendor on acquisition day, and it counts servers with any vulnerability rather than critical ones. The same firm's earlier published study put critical vulnerabilities closer to a third of servers. Both numbers point the same way; only one of them belongs in a board deck.

Should I switch to Qwen because it runs locally?

Switch nothing on the strength of a launch announcement. Test it on one real workload and measure whether output ships without correction. Also read the licence before you build anything durable on it — open-weight releases carry materially different terms, and some gate commercial use above a revenue threshold.

What is the single most urgent item here?

Article 50, because it is the only one with a date that has already passed. The MCP inventory and the local model test are important and can wait a week. A live, enforceable disclosure obligation that you are currently not meeting cannot.

Related Reading

The Five Eyes AI Agent Security Guide — governance-first architecture, and why the tool layer is where the exposure has always been.

You Don't Need an Agent, You Need a Rule — the four-category classification, and how every rule removes a tool permission you would otherwise have to govern.

Stop Chasing the Biggest Model — task-model matching and the advisor architecture, now runnable on a single consumer GPU.

The Government AI Threshold — how capability classification works in practice, and the template regulators keep returning to.

Apple Sues OpenAI, and the npm Attack on Developer Tooling — the supply-chain precedent that the MCP scan results extend.

AvePoint: 88.4% of Organisations Hit by Agent Security Incidents — the statistic that only makes sense once you stop looking at the model layer.

The No-Code Automation Workflow Guide — building workflows that stay documentable, which is now a compliance property as well as a maintenance one.

About the Author

Hamza Baig is the founder of Hexona Systems, an AI automation agency serving clients across six continents, and the AI Automation Institute, a community of more than 40,000 entrepreneurs building with AI.

He has been featured in the GHL Top 50, Yahoo Finance and Brainz Magazine, and writes regularly on automation architecture, agent governance and the operational realities of AI deployment.

Read more analysis on the Hamza Automates blog, or get in touch to discuss an automation build.

Follow @hamza_automates on Instagram for daily automation breakdowns.

Note: this article describes regulatory developments for a general business audience and is not legal advice. The author is not a lawyer. Obligations under the EU AI Act depend on your specific systems, role and jurisdiction—consult qualified counsel before acting.


About

Hamza Baig is the founder of Hexona Systems—an automation agency and softwareplatform that helps thousands of entrepreneurs and business owners implement AI-powered workflows at scale.

Share

Related Posts