As AI adoption gathers tempo, so does the evolution of the infrastructure that helps it. New requirements and connectors preserve showing, and those that catch on unfold by way of the ecosystem inside months reasonably than years. That pace strengthens what AI can do, however makes it very troublesome for safety groups to take care of enough protections.
MCP servers are a major instance. MCP grew to become the popular commonplace for connecting AI brokers to outdoors instruments and information inside 12 months of publication, and by December 2025 had been being utilized by each main coding assistant and most main LLMs. As a protocol, MCP has grown sooner than most infrastructure requirements, a rarity within the high-competition LLM house. This adoption curve validated MCP as Anthropic’s protocol of alternative for agent-tool connections, however safety options aren’t maintaining.
Numerous cybersecurity distributors are constructing merchandise to shut that hole. Lots of them describe what they’re constructing as an “AI firewall,” however that time period is doing double obligation proper now. One which means is an older, AI-powered firewall that defends a community in opposition to typical threats like malware and intrusion. The opposite, newer which means, and the one we’ll deal with right here, is a firewall constructed particularly to defend AI itself: its fashions, brokers, and the instruments they hook up with, from threats like immediate injection and information leakage. Verify Level’s AI Community Firewall, launched in July 2026, belongs to this second class.
Nowhere is the necessity for AI firewalls extra seen proper now than with MCP servers, the connectors that allow AI brokers attain outdoors instruments and information, and the fastest-growing piece of AI infrastructure that the sort of firewall now has to deal with.
How MCP grew to become AI’s default connector commonplace in a few 12 months
The expansion of MCP servers has been astonishing. Anthropic launched MCP as an open commonplace in November 2024. In December 2025, Anthropic introduced that greater than 10,000 active public MCP servers had been now operating, with deployment assist from AWS, Google Cloud, Azure, and different suppliers. All of the main AI platforms and coding assistants, together with ChatGPT, Gemini, Microsoft Copilot, Cursor and Visible Studio Code, now use MCP.
This fast progress is essentially because of the actual want for a standardised connection between AI programs and exterior instruments and information. The important thing benefit of an MCP server is that it permits AI brokers, assistants, and coding instruments to make use of a single interface to attach securely with a number of instruments and information sources, as an alternative of needing a customized connector.
However MCP introduced an entire new assault floor together with these benefits, at a pace that vastly outpaces any supporting safety community. Present AI defenses aren’t constructed for conditions the place AI brokers dynamically entry instruments and delicate programs, and as we’ll see, analysis findings present simply how huge that hole truly is.
What truly goes improper when an MCP server has a weak spot
OWASP, the Open Worldwide Software Safety Venture, has specified a lot of serious threats that can affect MCP servers. Device poisoning is a chief concern, taking immediate injection up a degree by embedding malicious directions in software descriptions, schemas, or software return values and utilizing them to govern agent behaviour.
Rug pull assaults are distinctive to the rising AI ecosystem. Right here, an attacker modifications a software’s definition after a human has already authorized it, exploiting the belief that approval created. Device shadowing and cross-origin escalation assaults work equally, with an attacker utilizing a malicious server’s software description to govern how an agent makes use of instruments belonging to a different, trusted server.
These vulnerabilities usually are not uncommon, both. An evaluation carried out by Lakera, the AI safety firm Verify Level acquired in 2025, reviewed 10,000 MCP servers and located that 40% carried exploitable weaknesses.
Different threats are acquainted however made extra sinister. Attackers use MCP servers for information exfiltration by covertly inserting delicate data into in any other case reputable software calls like searches and emails. Or they exploit the server’s broader permissions by granting it extra entry than the duty actually wants, creating a bigger publicity.
Why MCP safety is just not the identical as agent safety
Whereas MCP safety is significant, it’s not the entire image. Connecting by way of MCP servers is only one of many ways in which AI brokers can attain the instruments and information they want.
Securing them goes a great distance in direction of stopping software poisoning, unauthorised entry, and information breaches, however it’s not sufficient by itself. Brokers can nonetheless work together with different programs with out utilizing MCP in any respect.
This makes MCP safety only one thread in a broadly woven AI safety tapestry. When you think about distributors for an MCP server safety answer, you have to take a look at them throughout the larger context. It’s vital to judge how successfully they safe MCP-specific interactions and dangers, however you’ll nonetheless want extra controls to guard your AI ecosystem, so examine how properly the answer integrates with the remainder of your safety stack.
Who’s constructing for this hole proper now
The excellent news is that safety groups have choices. Numerous firms provide safety options that embrace MCP servers and keep in mind their position in AI infrastructure. TrueFoundry’s AI Gateway offers infrastructure-layer governance, entry management, and auditing for interactions between MCP instruments and brokers. Cisco has prolonged its AI Defense product to incorporate agent-facing guardrails, MCP scanning, and real-time inspection of MCP site visitors, designed to detect and block unsafe habits.
Check Point’s AI Network Firewall takes a unique strategy. Its providing is network-centric, stitching AI safety into its prospects’ present firewall infrastructure. The firewall addresses worker, AI utility, and AI agent interactions with MCP in addition to different connections between AI programs and exterior information and instruments. It discovers MCP servers, inspects MCP site visitors, and enforces insurance policies round agent entry.
Safety tends to lag each time infrastructure scales this quick, and MCP is following the identical sample. We’re at present seeing distributors and organisations attempting out totally different options to an rising drawback, whether or not that’s an AI-aware network-level firewall, infrastructure-level governance, or devoted AI guardrails. Which strategy wins out issues far lower than whether or not safety groups shut that hole earlier than an MCP-specific assault forces the difficulty.
