TL;DR: 61% of respondents are already using MCP with AI agents, 73% plan to expand use, and 77% of non-users expect to adopt it soon, while 30% rank security as the top factor shaping adoption, according to Astrix Security. The governance question is no longer whether MCP matters, but whether identity and policy can keep pace with agent activity.
Editorial analysis by NHI Mgmt Group, based on content published by Astrix Security: “The MCP Shift Part 3: The Future”.
By the numbers:
- 61% are using MCP with AI Agents today.
- 73% plan to expand their use of MCP.
- 77% of those not using MCP today plan to do so soon.
Key questions
Q: How should teams govern AI agents that use MCP?
A: Treat each connected agent as a non-human identity with an owner, a scope, and a review cycle.
Q: What breaks when MCP tools are treated as trusted by default?
A: When MCP tools are trusted by default, a poisoned or spoofed component can inherit privileged access, manipulate outputs, or expose secrets without crossing a traditional perimeter.
Q: Why do short-lived credentials matter more for agentic AI than for ordinary apps?
A: Agentic systems can request, use, and discard access inside a narrow runtime window, so long-lived credentials create unnecessary exposure between actions.
Practitioner guidance
- Define MCP as a governance boundary Make the MCP broker the place where agent identity is asserted, scope is issued, and audit is recorded across connected tools.
- Issue short-lived agent credentials Use audience-scoped tokens with the shortest practical lifetime so an agent cannot keep credentials beyond the current task.
- Restrict server trust by task type Approve specific MCP servers for specific work so agents do not inherit a generic route to every available tool.
Bottom line: MCP is shifting from a developer convenience layer into a governance boundary for AI agents, which changes where identity and policy must be enforced.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
MCP is becoming the policy enforcement layer for AI agents, not just an integration protocol. Once multiple tools are reachable through one abstraction, the control question moves from individual app permissions to centralised identity and authorization at the broker. That is a governance shift, not a convenience feature. Practitioners should treat MCP as the point where agent access either becomes governable or becomes invisible.
A few things that frame the scale:
- 24,008 unique secrets were exposed in MCP configuration files in 2025 alone, the protocol's first year of widespread adoption, according to the State of Secrets Sprawl 2026.
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: How do security teams know whether MCP server governance is working?
A: They should be able to answer four questions at any time: what servers exist, which are official, what credentials they can use, and what systems they contact. If those answers are unclear, governance is not working. The signal is not just fewer alerts, but clear attribution and scoped access across the fleet.
👉 Read our full editorial: MCP as an identity control plane for AI agents and governance