How are AI agents used? Evidence from 177,000 MCP tools
This paper analyzes 177,436 Model Context Protocol (MCP) tools to reveal that while software development dominates current AI agent usage, the proportion of tools performing direct actions has surged to 65%, highlighting the need for regulatory oversight that extends beyond model outputs to the tool layer to manage risks in consequential tasks like financial transactions.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine the world of Artificial Intelligence has just graduated from being a brilliant librarian to becoming a super-powered intern.
For a long time, AI (specifically Large Language Models) was like a librarian who could read millions of books, summarize them, and answer your questions perfectly. But it couldn't do anything. It couldn't book your flight, buy your groceries, or fix a bug in your code. It could only talk about it.
Now, we have AI Agents. These are the librarians who have been given a set of keys, tools, and a remote control. They can now walk out of the library, open your email, click buttons on a website, and even move physical objects (like drones) if you give them the right tools.
This paper is a massive inventory check of exactly what tools these new "interns" are being given. The researchers looked at 177,000 different tools (called "MCP tools") that developers have built between late 2024 and early 2026. They treated these tools like a public library catalog to see what kind of work these AI agents are actually being hired to do.
Here is the breakdown of their findings, using some everyday analogies:
1. The "Toolbox" is Exploding
Think of the AI ecosystem as a giant hardware store. In early 2025, this store had about 5,000 tools. By early 2026, the shelves were packed with 177,000 tools.
- The Trend: We are moving from tools that just let the AI look at things (like a camera) to tools that let the AI touch and change things (like a screwdriver or a paintbrush).
- The Shift: In 2024, most tools were for "Perception" (reading data). By 2026, 65% of the tools were for "Action" (doing things). The AI is no longer just watching the movie; it's now editing the film.
2. Who is Using These Interns? (The "Software" Dominance)
If you walked into this hardware store, you'd find that 67% of all the tools are for Software Development.
- The Analogy: It's like if you went to a construction site and found that 9 out of 10 workers were all building other tools for other workers.
- The Reality: Most AI agents are currently being used by programmers to write code, debug software, and manage IT systems. It's the "low-hanging fruit" because computers are easy for AI to understand.
- The Exception: There is a growing section of the store dedicated to Finance. While it's smaller than the software section, it's the most dangerous. These are tools that let AI agents move money, trade stocks, or handle crypto.
3. The "Controlled" vs. "Wild" Zones
The researchers noticed a scary trend in where these agents are allowed to work.
- The "Cage" (Constrained): Some tools only let the AI work in a specific, safe box. For example, a tool that only lets an AI check the balance of a specific bank account via a secure API. This is like a robot allowed to work only inside a glass cage.
- The "Wild West" (Unconstrained): More and more, developers are giving agents General-Purpose Tools. These are like giving the intern a master key to the whole building, a mouse, and a keyboard. They can browse the open web, click any button, and type anywhere.
- The Risk: The paper found that 94% of these "Wild West" tools are "Action" tools. This means the AI is increasingly allowed to wander the open internet and click buttons on any website, not just the safe, pre-approved ones. This is where mistakes (or hackers) can cause the most damage.
4. The "Self-Replicating" Problem
Here is the most mind-bending part: The interns are building their own tools.
- The Analogy: Imagine a construction crew where the workers are starting to build their own hammers and saws.
- The Data: In January 2025, only 6% of these tools were built with help from AI. By February 2026, that number skyrocketed to 62%.
- The Implication: AI is now helping to create the very tools that give AI more power. This creates a feedback loop. If an AI makes a mistake while building a tool, that bad tool gets used by other AIs, potentially spreading the error faster than humans can catch it.
5. Why Should You Care? (The "Bank Run" Scenario)
The paper argues that we need to watch these tools closely, like a security guard watching a vault.
- The Risk: If thousands of AI agents are all given the same "Action" tool to withdraw money from a bank, and they all decide to do it at the same time because of a glitch, it could cause a digital bank run.
- The Solution: Governments and regulators can't just watch the AI's "brain" (the chatbot); they need to watch its "hands" (the tools). By monitoring these public tool repositories, they can spot dangerous trends early. For example, they saw a massive spike in tools that allow AI to make cryptocurrency payments before those tools became common in the real world. This gave regulators a heads-up.
The Bottom Line
We are in the middle of a rapid transition. AI is evolving from a passive observer (reading and talking) into an active participant (clicking, buying, and building).
- Good News: It's making software development incredibly fast and efficient.
- Bad News: We are handing these powerful agents the keys to the entire digital kingdom, often without enough safety rails.
- The Warning: Because AI is now building its own tools and using them in "unconstrained" environments (like the open web), the potential for mistakes or malicious use is growing faster than our ability to understand it.
The paper suggests that to stay safe, we need to keep a close eye on the toolbox itself, not just the AI's conversation. If we see too many "keys to the front door" being handed out, we need to pause and ask: "Are we ready for this?"
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.