Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

MCP servers and agentic AI risk: what should teams change now?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15817
Topic starter  

TL;DR: RiskRubric v2 expands CSA risk evaluation from models into MCP servers and AI agents, adding controls for tool-call abuse, command injection, transitive trust, excessive agency, and data exposure across more than 20,000 publicly available MCP servers, according to AppSOC. The shift matters because agentic AI security now depends on governing tool-linked identity and privilege, not just model behaviour.

NHIMG editorial — based on content published by AppSOC: PointGuard AI and CSA Evolve RiskRubric v2 to Secure the Agentic AI Ecosystem

Questions worth separating out

Q: How should teams govern AI agents that use MCP?

A: Treat each connected agent as a non-human identity with an owner, a scope, and a review cycle.

Q: Why do conversational AI systems create new identity and access risks?

A: Because they can combine data retrieval, decision-making, and execution in a single interaction.

Q: What breaks when AI agents are given broad standing access?

A: Broad standing access breaks governance because the agent can move from one task to another without a fresh authorization check.

Practitioner guidance

  • Establish MCP server inventories Record every MCP server, its owner, its connected data sources, and the business workflows it can trigger.
  • Evaluate transitive trust before production use Test whether an agent inherits permissions, data access, or workflow reach through the server rather than through a direct policy grant.
  • Add runtime controls for agent tool use Constrain which tools an agent can invoke, what parameters it can pass, and which actions require approval.

What's in the full article

AppSOC's full blog covers the operational detail this post intentionally leaves for the source:

  • How RiskRubric v2 maps MCP-specific indicators across transparency, reliability, security, privacy, and excessive agency.
  • The full list of example assessment dimensions, including tool description fidelity, provider identity, provenance, and data exposure risks.
  • Details of the multi-scanner model and how contributors can submit evidence into the RiskRubric knowledge base.
  • The planned public access and on-demand testing workflow for evaluating newly discovered MCP servers.

👉 Read AppSOC's analysis of RiskRubric v2 and MCP security standards →

MCP servers and agentic AI risk: what should teams change now?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 15402
 

MCP governance is now an identity problem, not just an application integration problem. Once an AI system can reach enterprise applications through a protocol bridge, the question is who or what is authorised to act, at what scope, and with what delegated trust. That pushes MCP servers into the same governance conversation as service accounts, privileged tokens, and workload identity, because they mediate actionable access rather than passive data exchange. Practitioners should treat MCP adoption as an expansion of the identity perimeter, not as a feature of the model layer.

A few things that frame the scale:

  • 98% of companies plan to deploy even more AI agents within the next 12 months, despite documented rogue behaviour in 80% of current deployments, according to AI Agents: The New Attack Surface report.
  • Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation, according to AI Agents: The New Attack Surface report.

A question worth separating out:

Q: How do organisations evaluate whether an AI agent tool chain is safe enough?

A: They should test tool description fidelity, provenance, command handling, response exposure, and whether each connector introduces additional authority beyond the agent’s intended role. A safe tool chain is one where the trust path is explicit, limited, and auditable end to end.

👉 Read our full editorial: RiskRubric v2 extends MCP governance into agentic AI risk



   
ReplyQuote
Share: