.jpg)
SAN FRANCISCO, CA – August 5, 2026 — Nightfall AI, the AI-native data security platform, today published State of Agentic Data Security 2026, a research report built entirely from observed activity across enterprise environments rather than self-reported survey data. The report analyzes 88.9 million Model Context Protocol (MCP) events collected over a three-month period and identifies 608 distinct MCP-associated packages in active use, with one organization alone running nearly 200.
The report's central finding: the security tools most enterprises already run, including legacy DLP, CASB, and network gateways, were built to watch human behavior and cannot see how AI agents move data. Because agents read, transform, and route data through tool calls rather than uploads or messages, a large share of that activity never crosses a network boundary or triggers an existing control at all.
Key findings
- Nearly half of organizations run local MCP servers that communicate over standard input and output, invisible to any network-based control
- Roughly 70% of organizations were running at least one unsupported MCP server, including deprecated packages still connected to production databases
- Two in three observed MCP packages had no verified publisher
- Nearly 50% of organizations had credential-format strings sitting in MCP configuration files, outside any secret manager
- At least one in five organizations routed traffic to an official, trusted MCP endpoint through an unverified community proxy
- Twelve or more distinct agent clients were observed launching MCP servers, extending well beyond the IDEs most security teams currently govern
"Every mature category in data security was built on the same assumption: a person moves data, and a control inspects that action when they do it," said Rohan Sathe, CEO and co-founder of Nightfall AI. "AI agents break that assumption entirely. They move data at machine speed, through tool calls a person never initiates, and most of the industry hasn't caught up to what that means for visibility and control. This report is our attempt to make that gap measurable instead of theoretical."
Beyond the findings, the report lays out an 11-point framework for what full MCP coverage requires, an eight-table data appendix, and a Security Readiness Checklist that security teams can apply directly against their own environments.
State of Agentic Data Security 2026 is available now as a free download at https://www.nightfall.ai/state-of-agentic-data-security-2026
About Nightfall AI
Nightfall AI is the AI-native data security platform giving enterprises real-time control over sensitive data movement across humans and AI agents, MCP servers, SaaS, email, and endpoints. Legacy DLP was built for a world where people moved data through known channels. Nightfall was built for a world where AI agents move it too. Learn more at nightfall.ai.

