Permission Without Architecture
Researched by an agentic pipeline · reviewed and gated by the author
The tooling ecosystem has answered the capability question. The permission question remains entirely open.
The Permission Gap
When the UK AI Safety Institute catalogued 177,436 AI agent tools created between November 2024 and February 2026, the headline number was not the quantity. It was the direction. Action tools — those that modify external environments rather than merely observe them — grew from 27% to 65% of monthly downloads in sixteen months [S1]. The tooling that developers are actually adopting is overwhelmingly the kind that does things: executes code, controls browsers, moves money, writes to databases.
This is the first large-scale empirical measurement of what agent tools actually do, as distinct from what their makers announce. It proves that the capability question has been answered. The permission question — who authorises an agent to take consequential action, through what mechanism, with what accountability — has not.
What Was Measured
The AISI study drew on public Model Context Protocol server repositories across GitHub, Smithery, NPM and PyPI. Each tool was classified by direct impact — perception, reasoning or action — and by operational environment: constrained (working through a restricted API) or unconstrained (operating through browser automation, full computer control or unrestricted file access). The LLM-based classification was validated against human raters, achieving an inter-rater reliability of κ = 0.7 for the impact category [S1][S2].
The study was co-produced with the Bank of England, a detail whose significance becomes clear at the policy end of the evidence chain.
The Scale of the Shift
The raw growth is striking: from roughly 5,000 tools to 177,000 in a year, with monthly downloads surging from 80,000 to 14 million [S1]. But three structural findings matter more than volume.
First, the action shift is not uniform. Among commercial entities, action tools grew from 21% to 71% of downloads — steeper than the overall ecosystem [S4]. The tools that businesses reach for are disproportionately the ones that act.
Second, 95% of general-purpose tool downloads now involve action capabilities [S1]. General-purpose unconstrained tools grew from 41% to 50% of all downloads. The most adopted tools operate in the least controlled environments.
Third, payment-executing MCP servers grew from 47 to 1,578 in a single year, concentrated in cryptocurrency tools enabling direct, potentially irreversible transactions [S1][S2][S4]. And the proportion of new servers showing evidence of AI-assisted creation rose from 6% to 62% over the same period, with Claude Code accounting for roughly two-thirds of AI-coauthored servers [S1][S2]. Agents are building tools for other agents, at a pace no manual review process can match.
Where the Controls Are Not
The dominance of unconstrained environments is the finding that converts a technology trend into a governance problem. The tools gaining market share work through browser automation and computer control — not through the restricted API endpoints where enterprise security stacks operate.
In June 2026, the NSA and CISA published joint guidance confirming the architectural gap at the protocol level. MCP lacks enforced authentication, role-based access control and token lifecycle management. Authorisation remains optional. The agencies concluded that MCP’s security posture “remains uneven and highly dependent on implementation discipline rather than protocol guarantees” [S3]. CVE-2025-49596 demonstrated remote code execution in the MCP-Inspector toolchain, illustrating what happens when protocol-level enforcement is absent.
The Cloud Security Alliance reported that 65% of organisations experienced cybersecurity incidents tied to AI agent activity within the past year, with 35% reporting financial losses [S5]. Traditional data-loss prevention cannot inspect MCP traffic, because payloads consist of structured tool calls rather than the file formats DLP was designed to parse. Multi-hop agent workflows generate ten to twenty times the log volume of a human user yet fail to produce reconstructible audit trails for regulators [S5].
95% of general-purpose tool downloads involve action capabilities, yet MCP lacks enforced authentication, access control or authorisation at the protocol level.
What the Numbers Do Not Prove
The study’s authors are admirably explicit about the boundary of their evidence. Downloads, they note, “might mostly indicate which tools are piloted most by developers rather than tools deployed in routine production workflows” [S1]. No enterprise deployment, execution or outcome data exists in the study. No enterprise-scale governance failure has been directly attributed to the action-tool ecosystem shift.
The occupational consequentiality analysis, mapping tools against O*NET categories, rests on a weaker inter-rater reliability of κ = 0.32 for task-level mapping. Software development accounts for 67% of published tools and 90% of downloads [S2], meaning the measured shift is overwhelmingly a developer phenomenon. Whether it translates to equivalent adoption in finance, healthcare or legal domains remains undemonstrated. The geographic data, drawn from PyPI only, covers a single year with an acknowledged Western-centric bias.
These are material limitations. They do not diminish the core finding. The study proves that the available tooling has shifted decisively toward unconstrained action. Whether enterprise adoption follows the tooling, or governance catches up first, is the question the evidence frames but cannot answer.
The Institutional Response
The Bank of England’s co-production of the study lends institutional weight. In June 2026, the Bank’s Deputy Governor Sarah Breeden identified three governance gaps at an ECB forum: how users securely give consent and authorisation to agents for multiple transactions; how disputes are settled and liability assigned for erroneous or fraudulent transactions; and whether existing regulatory frameworks, “not built to contemplate autonomous agents,” are adequate [S6].
When a central bank’s Deputy Governor publicly names the absence of consent, liability and authorisation frameworks for AI agents, the governance gap has moved from a technical observation to a recognised institutional concern on a regulatory timeline.
The Judgement
The AISI study does not prove that enterprises have deployed autonomous agents in uncontrolled production environments at scale. It proves something that precedes and enables that deployment: the tooling ecosystem has shifted decisively toward action in unconstrained environments, the dominant tools bypass the integration points where existing controls operate, and no protocol-level permission architecture exists to govern what those tools do.
Three tests follow for any organisation permitting or considering AI agent adoption. Does your current security architecture cover the integration points where agent tools actually operate — browser automation, computer control, direct file access — or only the restricted API endpoints it was designed for? Do you have visibility into what agent tools your developers have already adopted, given that the ecosystem grows faster than any manual review can track? And have you defined who authorises an agent to take a consequential action — execute a payment, modify a record, deploy code — and through what enforceable mechanism?
The tooling ecosystem has answered the capability question. The permission question remains entirely open.
Sources
- AISI — “How are AI agents used? Evidence from 177,000 AI agent tools” — March 2026 — https://www.aisi.gov.uk/blog/how-are-ai-agents-used-evidence-from-177000-ai-agent-tools
- Stein, M. — “How are AI agents used? Evidence from 177,000 MCP tools” (arXiv 2603.23802) — March 2026 — https://arxiv.org/abs/2603.23802
- NSA/CISA — “Model Context Protocol (MCP): Security Design” — June 2026 — https://media.defense.gov/2026/Jun/02/2003943289/-1/-1/0/CSI_MCP_SECURITY.PDF
- Hughes, C. — Resilient Cyber — “Agents in Action: What 177,000 Tools Reveal About AI’s Shift from Thinking to Doing” — 2026 — https://www.resilientcyber.io/p/agents-in-action-what-177000-tools
- Nightfall AI — “Why MCP Breaks the Financial Services Security Stack” — 2026 — https://www.nightfall.ai/blog/why-mcp-breaks-the-financial-services-security-stack
- Breeden, S. — Bank of England — “Agents of change” speech at ECB Forum — June 2026 — https://www.bankofengland.co.uk/speech/2026/june/sarah-breeden-panel-at-the-european-central-bank-forum-on-central-banking-2026