TL;DR: Legacy DLP is not enough for AI agents because autonomous tool calls, MCP workflows, and desktop coding assistants create visibility and enforcement gaps that human-centric controls miss, according to Nightfall. The practical issue is not just detection, but whether security teams can block, coach, redact, and approve machine-speed data movement without breaking adoption.
NHIMG editorial — based on content published by Nightfall: Best AI Agent Security & MCP Security Platforms for AI Agent Access Control in 2026
By the numbers:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials.
- 53% of MCP servers expose credentials through hard-coded values in configuration files.
Questions worth separating out
Q: What breaks when AI agents are governed with legacy DLP controls?
A: Legacy DLP breaks because it assumes data moves through predictable human actions such as email, uploads, and endpoint copy events.
Q: Why do local AI agents complicate identity and access management?
A: They can retain legitimate permissions while changing timing, prioritisation, and action sequence outside human presence.
Q: How do organizations prove AI agent controls are actually working?
A: Organizations prove control effectiveness by showing which agents accessed which data, what actions they executed, and whether those actions stayed within approved task boundaries.
Practitioner guidance
- Map AI agent data paths to control points Inventory where agents reach data through SaaS, APIs, databases, desktop clients, and MCP tools, then assign a control owner to each path.
- Classify MCP tools by action risk Separate read, read-write, and destructive tool capabilities so agents do not inherit broad access by default.
- Extend governance to desktop and IDE clients Treat local AI assistants such as coding tools and desktop agents as governed enterprise endpoints, not personal productivity software.
What's in the full article
Nightfall's full guide covers the operational detail this post intentionally leaves for the source:
- Platform-by-platform feature comparison for AI agent access control across SaaS, endpoints, and MCP workflows
- Deployment and integration considerations for local clients such as Cursor, Claude Code, VS Code, and Claude Desktop
- Differences between monitoring-only models and real-time control models for blocking, coaching, redaction, and approval
- Use-case fit guidance for teams balancing desktop coverage, MCP enforcement, and deployment speed
👉 Read Nightfall's guide to AI agent and MCP security platforms →
AI agent and MCP security platforms: are your controls keeping up?
Explore further
Legacy DLP was designed for human-paced data movement, not agent-paced tool execution. The article’s core finding is that pattern matching, static rules, and post-event review do not map cleanly onto AI systems that chain actions across APIs, MCP tools, and desktop clients. The governance issue is not just visibility, but whether policy can follow the actor as it changes tools and context within a single workflow. Practitioners should treat agent runtime as a separate control plane.
A few things that frame the scale:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems, inappropriately sharing sensitive data, and revealing access credentials, according to AI Agents: The New Attack Surface report.
- Only 52% of companies can track and audit the data their AI agents access, which means 48% still cannot evidence what an agent touched during an investigation.
A question worth separating out:
Q: Who is accountable when a compromised AI agent misuses delegated access?
A: Accountability usually spans the business owner of the workflow, the team that issued or approved the credential, and the vendor if a third-party integration was involved. The critical governance question is not who logged in, but who allowed the delegation chain to exist and remain valid. That chain must be documented before incidents occur.
👉 Read our full editorial: AI agent and MCP security platforms expose a legacy DLP gap