The AI Exposure Index · July 2026
A grade means nothing until you know who else got one.
We graded the AI exposure of 2,706 organizations from the outside, using nothing but their domains. This is the distribution. Find your own grade at the bottom and read it against the population.
Where 2,706 organizations landed
Two thirds expose nothing. Almost everyone else is wide open. There is very little in between, and that is the finding: agent security is close to binary right now.
Nothing answers
No agent, MCP, or model surface responded to an unauthenticated request. Either there is nothing published, or everything published is gated.
Reachable, but gated
A surface exists and answers, but authentication holds. Ten organizations out of 2,706 landed here, which tells you how rare a deliberate agent perimeter still is.
63.4% of orgs scored better
Open and capable
An unauthenticated agent surface that lists real tools. A stranger can enumerate what it does and call it. No credential involved.
63.8% of orgs scored better
Open and destructive
The same thing, except the exposed tools write, spend, execute, or reach secrets. Reachability here is not a finding, it is an incident waiting for someone to notice.
94.7% of orgs scored better
The second axis: what holds the door
A grade compresses a lot. Underneath it, the single strongest predictor is authentication posture. Of 2,958 MCP servers we reached, 10% use OAuth.
A static API key is the band worth arguing about. It reads as security in a design review, travels in plaintext, and never expires. It is closer to nothing than to OAuth.
2,958 MCP servers reached · Guard0 AI-Register, July 2026
The third axis: what the open ones can actually do
Exposure only matters in proportion to capability. Across the 1,131 exposed servers that listed their tools, one in five offers something that writes or deletes.
Share of 1,131 tool-listing exposed servers · Guard0 AI-Register, July 2026
Free · passive · no login
Read your own grade against this.
Same agent, same method, same grading logic that produced every number on this page. Enter a domain and you are in the distribution in about a minute.
Want a person to walk the results with you? Request the free assessment.
How the index is built
The population is every organization publishing a remote MCP server in the public MCP Registry as of July 2026: 2,758 domains, of which 2,706 were reachable. Shared-hosting domains are excluded so one provider cannot skew a band.
For each domain we ran external discovery, an unauthenticated reachability probe, and a capability read of whatever the surface volunteered about itself. No tool was ever invoked. No credential was ever supplied. Everything here is what the internet returns to a stranger who knows your domain name.
The index is segmented by grade, authentication posture, and tool capability. It is deliberately not segmented by industry: the scan attributes surfaces to domains, and we have no sector mapping we trust across 2,706 of them. We would rather publish three axes we measured than a fourth we inferred.
The full grading logic is published in full, and the narrative analysis behind these figures is in The State of Exposed Agents.