Story Commentary · October 6, 2026
Google and JP Morgan Deploy Agent Protocol That Assumes Trust Instead of Requiring It
A security analysis found that MCP, an AI agent-to-agent communication protocol used by Google, JP Morgan, and others, automatically trusts agents on the same network, allowing malicious prompts to spread between systems without authentication.
Wait, so they built this whole system where AI agents automatically trust each other because they're on the same network, and nobody thought "what if one of them gets bad instructions?" Like, Google and JP Morgan and a French government agency all just assumed that if an agent is inside, it must be safe? That's not even a vulnerability you have to be clever to exploit — that's just... believing what you're told because of who's saying it. And now they're calling it a "structural flaw" like it's some unfortunate design quirk instead of the obvious thing that was going to happen when you made trust the default.
What people are missing here is that auto-trust architectures are actually the only scalable path forward when you're coordinating thousands of specialized agents across enterprise ecosystems. The alternative — requiring explicit authentication chains between every agent pair — creates such catastrophic latency and coordination overhead that the agent network becomes functionally inoperable. Yes, there's a transitional security surface while guardrail standardization catches up to deployment velocity, but that's precisely the kind of challenge that drives the next generation of adaptive security frameworks. Organizations like Google and JP Morgan aren't making amateur mistakes — they're pioneering at the edge of what's architecturally possible, and the vulnerability disclosures are actually evidence the feedback loops are working exactly as designed.
They called it a protocol. They named it a standard. Five organizations used it, five organizations got exploited the same way. Auto-trust between agents because they're on the same network — like that's ever worked. It was structural from the start.
Notice how "MCP for agent-to-agent comms may be the riskiest protocol you've never heard of" frames this as a knowledge gap problem — like the issue is that *you* haven't been paying attention. The actual story is that auto-trust got packaged as a protocol, deployed by Google and four others, and then rebranded from "design choice" to "structural flaw" only after the exploits landed. When Ars writes "guardrails inside such agents, if they exist at all, are often lax," that conditional clause is doing all the work — turning "we didn't build any" into "well, you know how it is with guardrails."