TL;DR: AI-BOMs are emerging as the inventory layer enterprises need to track model provenance, dataset lineage, tool integrations, and MCP connections before EU AI Act enforcement begins on August 2, 2026, according to Obot. Waiting to retrofit governance after shadow AI spreads leaves security teams unable to inventory or prove control over agent-driven access paths, which is now a compliance and identity problem, not just an AI tooling problem.
NHIMG editorial — based on content published by Obot: AI-BOM governance and MCP visibility for shadow AI
By the numbers:
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job.
- 53% of security leaders expect AI to run major portions of their infrastructure autonomously within the next three years.
- Only 44% of organisations have implemented any policies to manage their AI agents, despite 92% agreeing that governing AI agents is critical to enterprise security.
Questions worth separating out
Q: How should security teams govern MCP servers used by AI coding assistants?
A: Treat MCP servers as privileged trust boundaries, not simple data sources.
Q: Why do AI-BOMs matter when organisations already have software inventories?
A: Traditional software inventories describe components, but they usually miss the runtime relationships that matter in AI systems.
Q: What breaks when MCP connections are not discovered and tracked?
A: The organisation loses the ability to prove which AI system had access to which tool, data source, or credential path.
Practitioner guidance
- Inventory every AI and MCP connection continuously Audit agents, model integrations, and MCP server connections from code repositories, local configs, and production environments.
- Separate model approval from tool-connection approval Require a distinct review for each tool or data source an AI system can reach through MCP.
- Build provenance into intake workflow Collect model version, training-data source, dependency, and configuration details at intake rather than after deployment.
What's in the full article
Obot's full article covers the operational detail this post intentionally leaves for the source:
- A structured AI-BOM breakdown covering datasets, model metadata, software libraries, hardware resources, and configuration files.
- A step-by-step governance stack for discovery, intake, policy management, and audit logging across AI deployments.
- Practical guidance on where MCP visibility fits into continuous inventory maintenance and enforcement.
- The implementation logic behind building an approval workflow before the next AI deployment request arrives.
👉 Read Obot's analysis of AI-BOMs, MCP governance, and shadow AI →
AI-BOMs and MCP governance: what IAM teams need to fix?
Explore further