⟨ INCOMING TRANSMISSION ⟩ 200,000 MCP instances exposed by April 2026 security disclosure (OX Security) · 97M monthly MCP SDK downloads, up from ~2M at launch (Anthropic, Mar 2026) · RSAC 2026: $392M raised in agentic security in one week · EU AI Act fully applicable August 2026 · Microsoft (Apr 2026): MCP tool execution needs a control plane · sources: sentnelops.com/research/mcp-landscape · ⟨ INCOMING TRANSMISSION ⟩ 200,000 MCP instances exposed by April 2026 security disclosure (OX Security) · 97M monthly MCP SDK downloads, up from ~2M at launch (Anthropic, Mar 2026) · RSAC 2026: $392M raised in agentic security in one week · EU AI Act fully applicable August 2026 · Microsoft (Apr 2026): MCP tool execution needs a control plane · sources: sentnelops.com/research/mcp-landscape ·

[ RESEARCH // SOURCES ]

The MCP security landscape, with receipts.

Every statistic SentnelOps cites about the MCP ecosystem — on the homepage ticker and elsewhere — is listed here with its primary source. If a number can't be sourced, we don't use it.

200,000 MCP instances exposed by the April 2026 security disclosure

OX Security disclosed a systemic design flaw in the MCP STDIO transport default, estimating ~200,000 exposed MCP server instances across a supply chain of 150M+ package downloads, with arbitrary command execution confirmed on six live platforms. Anthropic confirmed the behavior is intentional, leaving remediation to downstream deployers.

97M monthly MCP SDK downloads, up from ~2M at launch

Anthropic reported in March 2026 that the official TypeScript and Python MCP SDKs reached 97 million combined monthly downloads, up from roughly 2 million at the protocol's November 2024 launch — a 16-month adoption curve comparable to foundational infrastructure standards.

RSAC 2026: $392M raised in agentic security in one week

Six companies announced a combined $392 million in agentic AI security funding in the week of RSAC 2026 (March 2026); startups building agentic AI defenses have raised a combined $3.6 billion.

EU AI Act fully applicable August 2026

The EU AI Act entered into force on August 1, 2024; general-purpose AI obligations applied from August 2025, and the regulation becomes fully applicable — including high-risk system obligations — on August 2, 2026. Organizations deploying autonomous agents against real systems inherit its documentation and control expectations.

Microsoft: MCP tool execution needs a control plane (April 2026)

Microsoft's developer division published "Securing MCP: A Control Plane for Agent Tool Execution" (April 22, 2026), introducing an open-source Agent Governance Toolkit and framing the core question exactly as runtime governance does: is this agent allowed to invoke this tool, with these arguments, at this time? Independent confirmation that per-call governance of MCP tool execution is becoming the category consensus.

Last reviewed September 2026. Corrections welcome: security@sentnelops.com. For the governance argument these numbers support, start with What is AI Agent Runtime Governance?