By NHI Mgmt Group Editorial TeamBased on Kong: “# Strategy & Connectivity in the Age of AI - An evening among peers, in Italy” (June 5, 2026)

TL;DR: As generative AI and agentic architectures push into API and data-path design, Kong’s workshop frames the operational question as how to govern models, agents, and flows at scale without sacrificing performance or security. The strategic issue is that connectivity now carries identity and authorisation risk, not just traffic management.


At a glance

What this is: This workshop is about AI data path governance for agents and APIs, with the central finding that connectivity design now has direct security and identity consequences.

Why it matters: It matters because IAM, API, and platform teams now have to govern model and agent traffic as a control plane, not just as a routing layer.


Context

AI data paths are the routes, policies, and controls that move prompts, model calls, tool invocations, and data between agents, APIs, and downstream systems. In this workshop context, the governance gap is that those paths are no longer just infrastructure plumbing; they now shape who or what can act, access, and transform data.

The article frames the problem around generative AI and agentic architectures, where API lifecycle management, security, and performance must be balanced together. For IAM and NHI practitioners, that means connectivity design is becoming part of the identity perimeter, especially when MCP and autonomous infrastructure are in the conversation.


Key questions

Q: How should organisations govern data and AI when teams are using models, agents, and fragmented data sources at the same time?

A: Organisations should unify governance across data, AI, and operational workflows instead of managing each use case in a separate silo. The goal is consistent visibility, control, and policy enforcement across every user and data source. That approach reduces duplication, improves trust in data, and gives teams a practical way to scale AI without multiplying governance gaps.

Q: Why do agentic AI systems increase risk for API security and governance?

A: Agentic AI increases risk because it can interpret context, make decisions, and execute multi-step actions without waiting for direct human approval. That autonomy is useful, but it also expands the blast radius of a mistake, bad prompt, or weak permission boundary. If an agent can reach sensitive APIs or data, governance must assume both intended and unintended actions will occur.

Q: Where do MCP-connected workflows create the biggest control gap?

A: The biggest gap is at tool invocation, where a model or agent can combine context and action faster than periodic review cycles can respond. If approvals, logging, and scope limits are not defined at that boundary, governance only sees the outcome after access has already been used.

Q: What should security teams prioritise when AI connectivity expands?

A: Security teams should prioritise ownership, inventory, and enforcement together. Without clear ownership, no one fixes drift. Without inventory, no one sees stale APIs or tool paths. Without runtime enforcement, inventory is only documentation. The effective programme is the one that connects all three at the point of access.


Background and context

How AI data paths become governance boundaries

An AI data path is the operational route between a caller, a model, and the systems that supply context or receive outputs. Once agents are in that path, every hop can become an authorisation decision, not just a transport event. That shifts the design problem from throughput alone to policy enforcement, request scoping, and traceability across APIs and tool calls. When the path is not explicit, teams tend to lose sight of which identity is allowed to invoke which function, with what context, and under what constraints.

Practical implication: treat the data path as a governed control surface and map each hop to an access decision.

API lifecycle management in agentic architectures

API lifecycle management in this context means governing the full set of APIs that agents, models, and platform services depend on over time, including introduction, change, retirement, and access scope. In agentic systems, that lifecycle matters because new tools and endpoints are often added faster than governance can track them. The result is a widening gap between what an agent can reach and what the organisation still intends it to use. Security and performance are coupled here: uncontrolled API growth creates both attack surface and operational drift.

Practical implication: inventory agent-facing APIs separately and retire unused endpoints before they become invisible access paths.

MCP and autonomous infrastructure change the trust model

MCP, the Model Context Protocol, connects AI agents to tools and data sources, which makes it a trust boundary as much as an integration layer. When the article links MCP with autonomous infrastructure, it is pointing to a future where connectivity decisions are increasingly embedded into runtime orchestration rather than isolated in human-run integration projects. That raises the bar for identity governance because the system may initiate access patterns dynamically. In practice, the risk is not only exposure, but also unreviewed expansion of what the agent can do as context changes.

Practical implication: define approval, logging, and scope boundaries around MCP-connected tools before agents begin using them at runtime.


NHI Mgmt Group analysis

AI connectivity is now an identity governance problem, not just an architecture problem. Once models and agents sit on the data path, the organisation is no longer only designing for latency and resilience. It is also deciding who can invoke what, which contexts are trusted, and where authorisation is enforced. That makes data-path governance a control-plane issue for IAM and NHI teams, not a side effect of application design. Practitioners should therefore evaluate AI traffic with the same discipline they apply to privileged connectivity.

API lifecycle management becomes the hidden failure mode in agentic systems. Agent deployments tend to add endpoints faster than governance can classify them, which creates unmanaged reachability over time. The risk is not limited to exposed interfaces; it is the accumulation of stale, forgotten, or over-scoped APIs that remain callable by active agents. This is a governance drift pattern, and it is difficult to spot if API inventory is not tied to identity and access review processes. Teams need to treat API retirement as an access-control event.

Model Context Protocol creates a new governance seam around dynamic tool access. MCP is valuable precisely because it makes tool and data access composable, but that composability also means the access boundary is no longer fixed at design time. A static least-privilege model struggles when the tool set can expand, contract, or be recombined at runtime. The practical conclusion is that governance must move closer to issuance and invocation rather than assuming stable entitlements. Identity programmes should classify MCP-connected tools as governed dependencies, not optional integrations.

AI data path governance will increasingly determine whether autonomous infrastructure is manageable at all. The article’s strategic framing suggests the market is moving from isolated AI experiments to platform-level control decisions. That changes what leaders need to ask: not whether AI can connect, but whether the connection can be governed, audited, and constrained without breaking delivery. This is where NHI, API, and platform governance converge. Practitioners should prepare for a world where path design is a core part of access design.

Runtime governance must replace assumptions about stable, human-paced integration work. The article implies a future where AI components may select and combine services faster than traditional review cycles can respond. That does not make existing controls obsolete, but it does expose their timing assumptions. Review-based governance remains useful only if it is paired with runtime enforcement and observability at the data path. Security teams should interpret this as a signal to tighten control at invocation time rather than relying on periodic assurance alone.

What this signals

AI data path governance will become a standard identity control problem. As agents and APIs converge, programmes will need to treat call paths, tool permissions, and context boundaries as part of identity governance rather than separate platform concerns. The organisations that align API lifecycle management with access oversight will have a clearer path to safe scaling.

The practical shift is from reviewing integrations after they exist to governing the conditions under which they can be created at all. That means tighter inventory discipline, stronger runtime policy, and clearer ownership across platform, security, and IAM teams.


For practitioners

  • Map AI data-path ownership Document which teams own the routes, APIs, and policies that move data between agents, models, and downstream systems. Tie each path to a named control owner so security reviews can focus on actual decision points rather than generic platform boundaries.
  • Inventory agent-facing APIs Create a separate inventory for APIs used by AI agents, including deprecated endpoints, hidden service calls, and tool-specific routes. Remove unused interfaces quickly so stale reachability does not become silent access exposure.
  • Define runtime policy for MCP tools Set explicit approval, logging, and scope rules for every tool exposed through MCP-connected workflows. Require the same governance clarity for tool invocation that you would expect for any privileged integration path.

Key takeaways

  • AI data paths are becoming governance boundaries because agents and APIs now carry authorisation risk as well as traffic.
  • API lifecycle management matters more in agentic environments because stale endpoints can become hidden access paths.
  • MCP-linked tool access needs runtime policy, logging, and scope controls if organisations want to keep connectivity governable.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 addresses the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Agentic AI Top 10ASI02 — Tool MisuseAgent and MCP tool access is the central governance issue in this workshop.
ASI03 — Identity & Privilege AbuseThe article centres on how agent identity and access scope must be governed across data paths.
Recommendation — Constrain tool reach and invocation rules so agents can only use approved actions at runtime. Bind agent identities to explicit privilege scopes and review them as part of access governance.
NIST AI RMFGOVERN — AI Governance and AccountabilityThe workshop is about governance structures for AI systems and their data paths.
Recommendation — Establish governance owners for AI connectivity, access policy, and accountability across the lifecycle.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsAI data-path governance depends on controlling who or what can access each service and API.
Recommendation — Apply PR.AA-05 to restrict agent and API entitlements to only the data paths they actually need.
NIST Zero Trust (SP 800-207)Principle of least privilege — Least privilegeThe workshop’s security framing depends on limiting trust across AI connectivity paths.
Recommendation — Enforce least privilege at each hop so AI traffic is continuously authorised rather than assumed trusted.

Key terms

  • AI Data Path: The AI data path is the route information takes as it moves into, through, and out of an AI system. It includes prompts, retrieved context, model inputs, outputs, logs, and downstream actions. Security teams use it to identify where sensitive data can be exposed, altered, or misused.
  • API Lifecycle Management: API lifecycle management is the practice of governing APIs from creation through versioning, change, retirement, and revocation. For security teams, the important part is tying identity controls to each phase so credentials, permissions, and integrations do not outlive the service they support. That keeps machine access from becoming permanent by default.
  • Model Context Protocol: Model Context Protocol is an open protocol that lets AI agents connect to tools and data sources. It expands what an agent can reach, so governance has to cover not only the model and its prompts, but also every system that can receive or return agent-driven data.
  • Autonomous Infrastructure Change: A machine-initiated modification to infrastructure settings, configurations, or access policies without a human approving each step in real time. The risk is not automation itself, but changes occurring faster than governance, review, and rollback processes can reliably detect or contain them.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 9, 2026.
Updated on October 10, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org