Nearly 16% of servers used by enterprise AI applications resolve to locations outside the United States, including Russia and China, creating what Ox Security calls a "silent enterprise governance gap" that undermines corporate cybersecurity controls. The findings come from a new Ox Security report titled *15,465 MCP Servers, 0 Governance*, which analyzed three public registries of Model Context Protocol servers—the standardized framework that connects AI applications to external tools and databases. The report warns that while MCP eliminates the need for developers to write custom integration code each time they link AI systems to APIs or data sources, it simultaneously exposes organizations to cloud security risks that data residency mandates, zero trust architectures, granular identity management policies, and continuous supply-chain audits are designed to prevent.
The analysis examined 5,095 unique hostnames across three public registries: mcp-official-registry, cline-marketplace, and github-mcp-registry. More than 2% of those hostnames no longer resolve to any server, with some currently unregistered and available for purchase, meaning an attacker could impersonate the servers they previously pointed to. When the Ox Security team tested Claude Code with Haiku 3.5 and granted a single "always-allow" permission, it enabled follow-on malicious activity without requiring human approval—a rogue MCP server first requested access to an innocuous file, the user approved it with always-allow permission, and the server then requested a sensitive file including .env and received it without further prompts.
"MCP has no protocol-level concept of geographic region," the report warns. An enterprise can enforce strict residency controls on its own cloud workloads while its AI agents connect freely to servers sitting outside those same controls. Anthropic's response to the always-allow permission issue, according to the report, was that once always-allow is granted, that's the documented behavior, and model-level detection of malicious content is a best-effort heuristic, not a security boundary. A June 2025 Backslash Security report analyzing 7,000 MCP servers found hundreds exposed to anyone on the same local network via a vulnerability dubbed "NeighborJack," with around 70 having severe flaws including unchecked input handling and excessive permissions. In April 2026, Ox Security released another report highlighting what it claimed is a "critical, systemic" vulnerability in MCP that could enable arbitrary command execution on any vulnerable system, potentially affecting as many as 200 open source projects, 150 million downloads, 7,000+ publicly accessible servers, and up to 200,000 vulnerable instances.
The governance gap stems from MCP's architectural design, which the April report described not as a traditional flaw but "an architectural design decision baked into Anthropic's official MCP SDKs across every supported programming language." Because MCP standardizes connections between AI applications and external resources, it removes the friction that previously forced developers to consider security implications each time they integrated a new data source or API. That convenience comes at a cost: organizations can enforce strict controls on their own infrastructure while their AI agents bypass those same safeguards by connecting to third-party MCP servers that sit outside corporate perimeters, don't adhere to data residency requirements, and operate without the granular access controls that govern internal systems. The protocol itself contains no mechanism to restrict connections based on geography, vendor trust level, or compliance status, leaving enterprises dependent on vendor-level detection that Anthropic itself characterizes as best-effort rather than a security boundary.
Anthropic dismissed the April vulnerability report as "expected behavior," leaving the AI supply chain to work on fixes to patch the individual open source projects which it impacts. The proliferation of MCP servers—nearly 16,000 analyzed in the latest report—means that as AI deployments accelerate, the governance gap widens, with more servers operating outside traditional security controls and more opportunities for threat actors to exploit unregistered hostnames, permissive always-allow configurations, and the absence of protocol-level geographic or trust boundaries. Organizations deploying AI agents via MCP face a choice between the protocol's development speed and the granular controls their existing security frameworks assume. For enterprises navigating rapid AI adoption, the tension between convenience and governance will likely intensify before any industry-wide standards emerge to reconcile the two.

