Join our Newsletter — 33% off our NHI Course

AI agent and MCP identity risk - are your controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: AI agents connected through MCP are taking actions across internal systems with elevated privileges, while organisations still struggle to monitor granted versus used access, according to Oasis Security. The governance gap is not technical novelty but identity scope, ownership, and logging that were built for slower, human-paced access models.

Editorial analysis by NHI Mgmt Group, based on content published by Oasis Security: “A real security challenge behind this artificial intelligence”.

By the numbers:

  • LLMs are used by over 90% of fortune 500 companies, according to Oasis Security.
  • The MCP repository has already been forked over 4,000 times, according to Oasis Security.

Key questions

Q: What breaks when AI agents are given broad standing access?

A: Broad standing access breaks governance because the agent can move from one task to another without a fresh authorization check.

Q: Why do AI agents create more governance risk than ordinary integrations?

A: AI agents can connect quickly, run continuously, and accumulate broad permissions across multiple services.

Q: What signs show that AI access sprawl is getting out of control?

A: Look for broad admin-consented permissions, agents targeting many services, unknown owners, dormant connections and disconnected approval records.

Practitioner guidance

  • Define ownership for every AI integration Assign a named business or technical owner to each agent, MCP server, or OAuth-connected tool so accountability survives deployment and staff turnover.
  • Review granted versus used permissions Compare approved scopes to actual runtime actions for each agent or integration, then tighten any access that is never exercised in practice.
  • Remove static secrets from AI configs Move API keys and tokens out of local configuration files, repositories, and shared builder workflows, because those locations routinely become accidental leak paths.

Bottom line: AI agents connected through MCP behave like high-risk machine identities because they can act, not just analyse.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 21 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 20880
 

AI agents connected through MCP are behaving like privileged NHIs, not like ordinary applications. The governance mistake is to treat them as convenience integrations while the runtime reality is broader system access, dynamic action, and background execution. Once an agent can both read and act, the identity model has to follow the behaviour, not the UI label. Practitioners should classify these integrations as high-risk machine identities and govern them accordingly.

A few things that frame the scale:

  • 24,008 unique secrets were exposed in MCP configuration files in 2025 alone, the protocol's first year of widespread adoption, according to the State of Secrets Sprawl 2026.
  • AI-related credential leaks surged 81.5% year-over-year in 2025, with the surrounding AI infrastructure leaking 5x faster than core LLM providers, according to the State of Secrets Sprawl 2026.

A question worth separating out:

Q: Should organisations prioritise access review or secret hygiene first for AI agents?

A: Secret hygiene should come first when API keys or tokens are embedded in configs, because exposed credentials can become immediate entry points. Access review still matters, but it is a slower control if the initial problem is that the credential itself is leaking into repositories or shared tooling.

👉 Read our full editorial: AI agent and MCP identity risk outpaces enterprise IAM controls


This post was modified 21 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.