Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

ChatGPT MCP connections: what it means for AI and identity teams


(@lalit)
Member Admin
Joined: 1 year ago
Posts: 264
Topic starter  

TL;DR: ChatGPT’s ability to connect to remote Model Context Protocol servers lowers the barrier to tool-triggering while expanding data exposure, approval, and supply-chain risk, according to Noma Security. The governance gap is not the protocol itself but the assumption that human-paced controls can safely supervise machine-triggered actions at scale.

NHIMG editorial — based on content published by Noma Security: ChatGPT MCP access expands the attack surface for AI governance

By the numbers:

Questions worth separating out

Q: How should security teams govern MCP servers used by AI coding assistants?

A: Treat MCP servers as privileged trust boundaries, not simple data sources.

Q: When do AI tool integrations become a privileged access risk?

A: They become privileged access risk whenever the AI can reach sensitive systems, move data across trust boundaries, or execute write actions.

Q: What do organisations get wrong about approval for AI actions?

A: They often assume a single approval step is enough for a whole conversation.

Practitioner guidance

  • Establish an approved MCP inventory Create a centrally managed list of permitted MCP servers, grouped by data sensitivity, business purpose, and write capability so every connection has an owner and review cycle.
  • Separate read and write permissions Block write-capable MCP actions unless the workflow has explicit per-action approval, because conversation-level approval is too broad for privileged operations.
  • Log every tool call and context transfer Capture the server identity, action type, request payload, and approval decision for each MCP interaction so investigations can reconstruct what the AI exposed or changed.

What's in the full article

Noma Security's full blog post covers the operational detail this post intentionally leaves for the source:

  • Practical guidance on how to vet remote MCP servers before allowing production use
  • Specific recommendations for supervising write-capable AI actions at the approval step
  • Examples of runtime protection and kill-switch patterns for destructive AI behaviour
  • Policy language ideas for employee education, escalation, and audit logging

👉 Read Noma Security's analysis of ChatGPT MCP governance and AI tool risk →

ChatGPT MCP connections: what it means for AI and identity teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 2 months ago
Posts: 11961
 

Remote MCP access turns a chat interface into an NHI governance problem. Once an AI session can trigger tools against external servers, the security unit is no longer a prompt but an identity-bearing access path. That shifts control expectations from conversational safety to authorisation, logging, and server trust. Practitioners should treat every connected MCP server as a governed non-human identity dependency, not as an optional integration.

A few things that frame the scale:

  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
  • 92% agree governing AI agents is critical to enterprise security, yet only 44% have implemented any policies to do so.

A question worth separating out:

Q: Who is accountable when an AI assistant overshares sensitive content?

A: Accountability sits with the team that owns the policy, the attribute feeds, and the enforcement points, because ABAC only works when all three are managed together. If any one of them is missing, the organisation has not built a defensible control path, even if the model itself appears constrained.

👉 Read our full editorial: ChatGPT MCP access expands the attack surface for AI governance



   
ReplyQuote
Share: