Join our Newsletter — 33% off our NHI Course

MCP bypass and AI agent governance: are your controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: MCP can only enforce policy, intent, and audit when agents actually route through it, but direct API calls, headless browser automation, and shadow connectors can bypass those controls and leave security teams blind, according to Strata Identity. The real issue is not the protocol itself but the assumption that agents will stay inside it, which breaks once identity is optional.

Editorial analysis by NHI Mgmt Group, based on content published by Strata Identity: “Prevent MCP Bypass”.

Key questions

Q: What breaks when AI agents bypass a centralized MCP gateway?

A: When agents bypass a centralized MCP gateway, security controls fragment across notebooks, scripts, and individual servers.

Q: Why do direct API calls and browser automation create so much risk for AI agents?

A: They move execution outside the mediation layer where identity controls are usually enforced.

Q: How do you know if MCP security controls are actually working?

A: You know MCP controls are working when untrusted endpoints are blocked, privileged tool calls are minimal, and audit logs show only approved commands and data flows.

Practitioner guidance

  • Make MCP the only enforceable access path Block direct API and browser access paths that do not present MCP attestation, and test that the control fails closed under bypass attempts.
  • Bind tokens to the mediation session Issue short-lived, scoped tokens that are cryptographically tied to the MCP bridge session so credentials cannot be replayed outside the control plane.
  • Extend identity controls into web sessions Require strong authentication, embedded identity orchestration, and bot detection for browser-based agent activity so UI automation is not a blind spot.

Bottom line: MCP only governs AI agents when the organisation can prevent alternative paths from reaching the same systems.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 5 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21367
 

Identity mediation is only real when there are no viable side doors. MCP does not become a governance control simply because it exists in the stack. If agents can reach the same API, web app, or workflow through an unmediated path, then policy, intent binding, and audit are conditional, not authoritative. The practitioner lesson is to govern the entire access surface, not the preferred one.

A few things that frame the scale:

  • 24,008 unique secrets were exposed in MCP configuration files in 2025 alone, the protocol's first year of widespread adoption, according to the State of Secrets Sprawl 2026.
  • 7% of security leaders admit they do not know how often their AI systems are making autonomous changes to infrastructure, according to the 2026 Infrastructure Identity Survey.

A question worth separating out:

Q: How should teams govern AI agents that can reach APIs, events, and memory?

A: Teams should govern those agents as runtime identities, not as isolated integrations. That means enforcing policy at execution time, logging every tool and data access, and binding actions back to a clear initiating workflow or identity. If the control plane cannot show who acted, what they reached, and why, the programme does not have usable governance.

👉 Read our full editorial: MCP bypass risks are exposing AI agent identity controls


This post was modified 5 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.