Skip to content

The AI Exposure Index · July 2026

A grade means nothing until you know who else got one.

We graded the AI exposure of 2,706 organizations from the outside, using nothing but their domains. This is the distribution. Find your own grade at the bottom and read it against the population.

Population 2,706 orgsMethod passive, read-onlyTools invoked zero
48.6%
of organizations expose an agent surface with no authentication
13,606
tools callable by a stranger, no token, no OAuth
437
exposed servers also reachable from any web page, CORS wide open

Where 2,706 organizations landed

Two thirds expose nothing. Almost everyone else is wide open. There is very little in between, and that is the finding: agent security is close to binary right now.

A
D
A 1,716 · 63.4%
B 10 · 0.4%
D 836 · 30.9%
F 144 · 5.3%
A1,716 orgs

Nothing answers

No agent, MCP, or model surface responded to an unauthenticated request. Either there is nothing published, or everything published is gated.

B10 orgs

Reachable, but gated

A surface exists and answers, but authentication holds. Ten organizations out of 2,706 landed here, which tells you how rare a deliberate agent perimeter still is.

63.4% of orgs scored better

D836 orgs

Open and capable

An unauthenticated agent surface that lists real tools. A stranger can enumerate what it does and call it. No credential involved.

63.8% of orgs scored better

F144 orgs

Open and destructive

The same thing, except the exposed tools write, spend, execute, or reach secrets. Reachability here is not a finding, it is an incident waiting for someone to notice.

94.7% of orgs scored better

The second axis: what holds the door

A grade compresses a lot. Underneath it, the single strongest predictor is authentication posture. Of 2,958 MCP servers we reached, 10% use OAuth.

A static API key is the band worth arguing about. It reads as security in a design review, travels in plaintext, and never expires. It is closer to nothing than to OAuth.

Nothing at all
answers any request
1,139 · 39%
Static API key
plaintext, never expires
134 · 5%
OAuth, short-lived
the only posture that holds
296 · 10%
Gated or unreachable
no response to probe
1,389 · 47%

2,958 MCP servers reached · Guard0 AI-Register, July 2026

The third axis: what the open ones can actually do

Exposure only matters in proportion to capability. Across the 1,131 exposed servers that listed their tools, one in five offers something that writes or deletes.

Write / destructive
create · update · delete
230 · 20%
Comms / outbound
send · email · webhook
102 · 9%
Payments / money
charge · transfer · payout
94 · 8%
Filesystem
read · write · upload
92 · 8%
Code / command exec
exec · run · shell
76 · 7%
Secrets / credentials
token · apikey · env
52 · 5%
Infra / admin
deploy · terminate · db
24 · 2%

Share of 1,131 tool-listing exposed servers · Guard0 AI-Register, July 2026

Free · passive · no login

Read your own grade against this.

Same agent, same method, same grading logic that produced every number on this page. Enter a domain and you are in the distribution in about a minute.

Want a person to walk the results with you? Request the free assessment.

How the index is built

The population is every organization publishing a remote MCP server in the public MCP Registry as of July 2026: 2,758 domains, of which 2,706 were reachable. Shared-hosting domains are excluded so one provider cannot skew a band.

For each domain we ran external discovery, an unauthenticated reachability probe, and a capability read of whatever the surface volunteered about itself. No tool was ever invoked. No credential was ever supplied. Everything here is what the internet returns to a stranger who knows your domain name.

The index is segmented by grade, authentication posture, and tool capability. It is deliberately not segmented by industry: the scan attributes surfaces to domains, and we have no sector mapping we trust across 2,706 of them. We would rather publish three axes we measured than a fourth we inferred.

The full grading logic is published in full, and the narrative analysis behind these figures is in The State of Exposed Agents.

Guard0 / accountability systemG0-RES-IDXguard0.ai/research/exposure-index2,706 organizationsPassive external scanUpdated continuously
Unresolved