ConciseSignal

MCP access policies found widely broken or missing

A review reported by The New Stack found that one in five Model Context Protocol (MCP) access policies were either nonfunctional or absent. Security risks included servers operating with overly broad permissions, vulnerabilities to malicious instructions, and widespread use of rarely-rotated static tokens or personal credentials. An update to MCP's specification in July 2026 focused on tighter authorization, acknowledging major flaws in earlier trust models.

Why it mattersWeak or missing access controls in core AI infrastructure can expose sensitive data and systems to unauthorized access or manipulation. The scale of these gaps suggests persistent industry-wide risk, even after protocol updates.

Sources covering this

The New StackWe found that 1 in 5 MCP access policies came back broken or missing3:00 PM
Concise Signal DailyEverything that mattered, every weekday at 7am.

More in AI

18 sources · 4d ago

OpenAI rolls out GPT-6 Astra to most paying users

OpenAI has made its new GPT-6 Astra model available to most paying subscribers a day after its official launch. The rollout, initially described as “messy” by OpenAI’s CEO, now includes ChatGPT Plus, Business, Pro, and Enterprise users, while customers on the lower-priced Go tier do not have access. Astra is also available via the API. OpenAI says the rollout required bringing new systems and additional computing resources online.

6 sources · 2d ago

ChatGPT Images 2.5 adds faster editing tools

OpenAI has updated its ChatGPT Images feature to version 2.5, adding several new editing tools and speeding up image generation. You can now remove backgrounds, resize images to preset dimensions, erase items by brushing over them, and use markup and comment functions directly from a new Edit toolbar. According to TechRadar, the features are available in both web and app versions, though OpenAI hasn't formally announced the rollout yet.

14 sources · 2d ago

Anthropic researcher resigns, warns of AI race risks

Jacob Coxon, who worked on AI training at Anthropic and previously OpenAI, resigned this week. He posted that large AI firms are 'gambling with our lives' by pushing towards systems they may not be able to control. Coxon says both companies know the risks but feel locked in a race to develop powerful AI anyway. He called for drastic steps like a pause on new model improvements.

1 sources · 27m ago

Google Cloud releases plugin for AI coding agents

Google Cloud has rolled out a new plugin that lets AI coding agents more easily use Google Cloud services and tools. The plugin comes as a prepackaged bundle, so AI assistants can handle tasks like authentication, managing projects, and referencing official docs without complex setup. It's built to work across platforms using an open, vendor-neutral standard for AI agent plugins.